CVE-2022-27497

Null pointer dereference in firmware for Intel(R) AMT before version 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 may allow an unauthenticated user to potentially enable denial of service via network access.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.6 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
intelCNA
8.6 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 52%
VendorProductVersion
intelactive_management_technology_firmware
𝑥
< 11.8.93
intelactive_management_technology_firmware
11.12.0 ≤
𝑥
< 11.12.93
intelactive_management_technology_firmware
11.22.0 ≤
𝑥
< 11.22.93
intelactive_management_technology_firmware
12.0 ≤
𝑥
< 12.0.92
intelactive_management_technology_firmware
14.1 ≤
𝑥
< 14.1.67
intelactive_management_technology_firmware
15.0 ≤
𝑥
< 15.0.42
intelactive_management_technology_firmware
16.1.0 ≤
𝑥
< 16.1.25
𝑥
= Vulnerable software versions