CVE-2021-33159

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
11/11/2022
Last modified:
05/02/2025

Description

Improper authentication in subsystem for Intel(R) AMT before versions 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 may allow a privileged user to potentially enable escalation of privilege via local access.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:intel:active_management_technology_firmware:*:*:*:*:*:*:*:* 11.8.93 (excluding)
cpe:2.3:o:intel:active_management_technology_firmware:*:*:*:*:*:*:*:* 11.12.0 (including) 11.12.93 (excluding)
cpe:2.3:o:intel:active_management_technology_firmware:*:*:*:*:*:*:*:* 11.22.0 (including) 11.22.93 (excluding)
cpe:2.3:o:intel:active_management_technology_firmware:*:*:*:*:*:*:*:* 12.0 (including) 12.0.92 (excluding)
cpe:2.3:o:intel:active_management_technology_firmware:*:*:*:*:*:*:*:* 14.1 (including) 14.1.67 (excluding)
cpe:2.3:o:intel:active_management_technology_firmware:*:*:*:*:*:*:*:* 15.0 (including) 15.0.42 (excluding)
cpe:2.3:o:intel:active_management_technology_firmware:*:*:*:*:*:*:*:* 16.1.0 (including) 16.1.25 (excluding)