CVE Feed

    Dashboard / CVE / CVE-2023-38587

    CVE-2023-38587

    Improper input validation in some Intel NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.

    Published:Jan 19, 2024
    Last Modified:Jun 17, 2025
    EPS:Jan 19, 2024
    EPSS Score:0.00053
    CVSS Score:7.5

    Affected Products

    Vendor
    Intel
    Product
    Nuc 8 Enthusiast Nuc8i7behga
    Vendor
    Intel
    Product
    Nuc 8 Enthusiast Nuc8i7behga Firmware
    Vendor
    Intel
    Product
    Nuc 8 Enthusiast Nuc8i7bekqa
    Vendor
    Intel
    Product
    Nuc 8 Enthusiast Nuc8i7bekqa Firmware
    Vendor
    Intel
    Product
    Nuc 8 Home Nuc8i3behfa
    Vendor
    Intel
    Product
    Nuc 8 Home Nuc8i3behfa Firmware
    Vendor
    Intel
    Product
    Nuc 8 Home Nuc8i5behfa
    Vendor
    Intel
    Product
    Nuc 8 Home Nuc8i5behfa Firmware
    Vendor
    Intel
    Product
    Nuc 8 Home Nuc8i5bekpa
    Vendor
    Intel
    Product
    Nuc 8 Home Nuc8i5bekpa Firmware
    Vendor
    Intel
    Product
    Nuc Kit Nuc8i3beh
    Vendor
    Intel
    Product
    Nuc Kit Nuc8i3beh Firmware
    Vendor
    Intel
    Product
    Nuc Kit Nuc8i3behs
    Vendor
    Intel
    Product
    Nuc Kit Nuc8i3behs Firmware
    Vendor
    Intel
    Product
    Nuc Kit Nuc8i3bek
    Vendor
    Intel
    Product
    Nuc Kit Nuc8i3bek Firmware
    Vendor
    Intel
    Product
    Nuc Kit Nuc8i5beh
    Vendor
    Intel
    Product
    Nuc Kit Nuc8i5beh Firmware
    Vendor
    Intel
    Product
    Nuc Kit Nuc8i5behs
    Vendor
    Intel
    Product
    Nuc Kit Nuc8i5behs Firmware
    Vendor
    Intel
    Product
    Nuc Kit Nuc8i5bek
    Vendor
    Intel
    Product
    Nuc Kit Nuc8i5bek Firmware
    Vendor
    Intel
    Product
    Nuc Kit Nuc8i7beh
    Vendor
    Intel
    Product
    Nuc Kit Nuc8i7beh Firmware
    Vendor
    Intel
    Product
    Nuc Kit Nuc8i7bek
    Vendor
    Intel
    Product
    Nuc Kit Nuc8i7bek Firmware

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High