CVE-2023-22305
Memory Safety in Intel Aptio V Uefi Firmware Integrator Tools 5.27.03.0003 … 5.27.06.0017
Raw vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:HSummary
CVE-2023-22305 is a medium-severity Integer Overflow to Buffer Overflow (CWE-680) vulnerability in Intel Aptio V Uefi Firmware Integrator Tools. Its CVSS base score is 6.5 (Medium).
Operationally, ranked at the 11th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2023-26468
Vulnerability Data
Integer overflow in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable denial of service via local access.
- CWE(s)
Related Threats
CVEs Like This One
Affected Assets
Mitigating Controls
Control response
—
—
—
V5.2.6
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Secure SDLC practices directly prevent integer-overflow flaws during development, but eliminating only this CWE covers only part of the broad control intent.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Security testing can detect integer-overflow-to-buffer-overflow conditions during development.
Secure development life cycle mandates practices that can catch integer overflows before deployment.
Application security requirements can specify safe integer handling and bounds checking.
Secure architecture principles encourage use of safe arithmetic libraries and overflow detection.
Secure coding standards directly require prevention of integer overflows that lead to buffer overflows.