CVE-2022-21933

ASUS VivoMini/Mini PC device has an improper input validation vulnerability. A local attacker with system privilege can use system management interrupt (SMI) to modify memory, resulting in arbitrary code execution for controlling the system or disrupting service.
References
Link Resource
https://www.twcert.org.tw/tw/cp-132-5547-34bc4-1.html Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:asus:vc65-c1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:vc65-c1:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:asus:pb60v_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:pb60v:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:asus:pb60g_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:pb60g:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:asus:pb60s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:pb60s:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:asus:pa90_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:pa90:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:asus:pb50_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:pb50:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:asus:pb60_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:pb60:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:asus:pb61v_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:pb61v:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:asus:ts10_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:ts10:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:asus:pn40_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:pn40:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:asus:pn60_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:pn60:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:asus:pn30_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:pn30:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:asus:un65u_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:un65u:-:*:*:*:*:*:*:*

History

24 Jul 2023, 13:53

Type Values Removed Values Added
CWE CWE-20 CWE-787

Information

Published : 2022-01-21 09:15

Updated : 2024-02-28 18:48


NVD link : CVE-2022-21933

Mitre link : CVE-2022-21933

CVE.ORG link : CVE-2022-21933


JSON object : View

Products Affected

asus

  • pa90_firmware
  • ts10_firmware
  • pb60g
  • ts10
  • pb60v_firmware
  • pb50
  • pb61v_firmware
  • vc65-c1
  • un65u
  • pn40
  • pn60
  • pb60s
  • pa90
  • pb60
  • pn60_firmware
  • pb61v
  • vc65-c1_firmware
  • pb50_firmware
  • pb60v
  • pb60s_firmware
  • pb60g_firmware
  • pn30_firmware
  • pb60_firmware
  • pn30
  • un65u_firmware
  • pn40_firmware
CWE
CWE-787

Out-of-bounds Write

CWE-20

Improper Input Validation