CVE-2022-38087

MEDIUM

Intel(R) Processors - Info Disclosure

Title source: llm

Description

Exposure of resource to wrong sphere in BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.

Scores

CVSS v3 4.1
EPSS 0.0005
EPSS Percentile 14.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-668
Status published

Affected Products (50)

intel/xeon_e-2314_firmware
intel/xeon_e-2324g_firmware
intel/xeon_e-2334_firmware
intel/xeon_e-2336_firmware
intel/xeon_e-2356g_firmware
intel/xeon_e-2374g_firmware
intel/xeon_e-2378_firmware
intel/xeon_e-2378g_firmware
intel/xeon_e-2386g_firmware
intel/xeon_e-2388g_firmware
intel/xeon_e-2226ge_firmware
intel/xeon_e-2254me_firmware
intel/xeon_e-2254ml_firmware
intel/xeon_e-2276me_firmware
intel/xeon_e-2276ml_firmware
... and 35 more

Timeline

Published May 10, 2023
Tracked Since Feb 18, 2026