Cyber Resilience

CVE-2023-40540

Intel Nuc 11 Pro Kit Nuc11Tnkv50Z Firmware

Published
14 November 2023
Modified
21 November 2024
Patch / advisory
CVSS Score v3.1 4.1
Click a component to see what it means
Raw vectorCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
EPSS Score 0.0021 11th percentile
Risk Priority 35 floored blend · peak EPSS

Summary

CVE-2023-40540 is a medium-severity Non-Transparent Sharing of Microarchitectural Resources (CWE-1303) vulnerability in Intel Nuc 11 Pro Kit Nuc11Tnkv50Z Firmware. Its CVSS base score is 4.1 (Medium).

Operationally, ranked at the 11th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

Non-Transparent Sharing of Microarchitectural Resources in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable information disclosure via local access.

CWE(s)

Related Threats

CVEs Like This One

CVE-2023-22444Same product: Intel Nuc 11 Enthusiast Kit Nuc11Phki7C
CVE-2023-27887Same product: Intel Nuc 11 Pro Board Nuc11Tnbi3
CVE-2023-29494Same product: Intel Nuc 11 Pro Board Nuc11Tnbi3
CVE-2023-22312Same product: Intel Nuc 11 Enthusiast Kit Nuc11Phki7C
CVE-2023-29500Same product: Intel Nuc 11 Performance Kit Nuc11Pahi3
CVE-2023-22330Same product: Intel Nuc 11 Performance Kit Nuc11Pahi3
CVE-2024-25561Same product: Intel Nuc M15 Laptop Kit Lapbc510
CVE-2023-22449Same product: Intel Nuc 11 Performance Kit Nuc11Pahi3
CVE-2023-34349Same product: Intel Nuc 11 Performance Kit Nuc11Pahi3
CVE-2024-34163Same product: Intel Nuc X15 Laptop Kit Lapkc51E

Affected Assets

intel
nuc 11 pro kit nuc11tnkv50z firmware
all versions
intel
nuc 11 pro kit nuc11tnhv70l firmware
all versions
intel
nuc 11 pro kit nuc11tnhv50l firmware
all versions
intel
nuc 11 pro board nuc11tnbv7 firmware
all versions
intel
nuc 11 pro kit nuc11tnkv5 firmware
all versions
intel
nuc 11 pro kit nuc11tnkv7 firmware
all versions
intel
nuc 11 pro kit nuc11tnhv5 firmware
all versions
intel
nuc 11 pro mini pc nuc11tnkv5 firmware
all versions
intel
nuc 11 pro mini pc nuc11tnkv7 firmware
all versions
intel
nuc 11 pro kit nuc11tnhv7 firmware
all versions
+46 more product configuration(s) — see NVD for full list

Mitigating Controls

Mitigating Controls (NIST CSF 2.0) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.

DE.CM-09 partial match
prevents

Runtime monitoring of hardware can detect anomalous cache/branch behavior caused by the weakness.

ID.RA-09 partial match
prevents

Hardware authenticity/integrity assessment before acquisition can identify and avoid CPUs with unsafe microarchitectural sharing.

PR.PS-03 partial match
prevents

Replacing hardware that lacks needed security capabilities directly targets CPUs whose shared resources violate isolation.

Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.

mitigates

Secure system architecture principles can mandate hardware-level isolation of microarchitectural resources.

detects

Security testing can detect side-channel leakage but does not prevent the underlying microarchitectural sharing.

none

Secure coding can avoid software patterns that amplify microarchitectural side-channels but does not address the hardware sharing itself.

References