CVE-2022-27497

EUVD-2022-31998
Null pointer dereference in firmware for Intel(R) AMT before version 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 may allow an unauthenticated user to potentially enable denial of service via network access.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.6 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
intelCNA
8.6 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 66%
Affected Products (NVD)
VendorProductVersion
intelactive_management_technology_firmware
𝑥
< 11.8.93
intelactive_management_technology_firmware
11.12.0 ≤
𝑥
< 11.12.93
intelactive_management_technology_firmware
11.22.0 ≤
𝑥
< 11.22.93
intelactive_management_technology_firmware
12.0 ≤
𝑥
< 12.0.92
intelactive_management_technology_firmware
14.1 ≤
𝑥
< 14.1.67
intelactive_management_technology_firmware
15.0 ≤
𝑥
< 15.0.42
intelactive_management_technology_firmware
16.1.0 ≤
𝑥
< 16.1.25
𝑥
= Vulnerable software versions