CVE-2022-21933

ASUS VivoMini/Mini PC device has an improper input validation vulnerability. A local attacker with system privilege can use system management interrupt (SMI) to modify memory, resulting in arbitrary code execution for controlling the system or disrupting service.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.7 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
twcertCNA
6.7 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 6%
VendorProductVersion
asusvc65-c1_firmware
𝑥
< 1302
asuspb60v_firmware
𝑥
< 1302
asuspb60g_firmware
𝑥
< 1302
asuspb60s_firmware
𝑥
< 1302
asuspa90_firmware
𝑥
< 1401
asuspb50_firmware
𝑥
< 902
asuspb60_firmware
𝑥
< 1502
asuspb61v_firmware
𝑥
< 601
asusts10_firmware
𝑥
< 609
asuspn40_firmware
𝑥
< 2201
asuspn60_firmware
𝑥
< 808
asuspn30_firmware
𝑥
< 320
asusun65u_firmware
𝑥
< 618
𝑥
= Vulnerable software versions