CVE-2022-27497

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
11/11/2022
Last modified:
05/02/2025

Description

Null pointer dereference in firmware for Intel(R) AMT before version 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 may allow an unauthenticated user to potentially enable denial of service via network access.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:intel:active_management_technology_firmware:*:*:*:*:*:*:*:* 11.8.93 (excluding)
cpe:2.3:o:intel:active_management_technology_firmware:*:*:*:*:*:*:*:* 11.12.0 (including) 11.12.93 (excluding)
cpe:2.3:o:intel:active_management_technology_firmware:*:*:*:*:*:*:*:* 11.22.0 (including) 11.22.93 (excluding)
cpe:2.3:o:intel:active_management_technology_firmware:*:*:*:*:*:*:*:* 12.0 (including) 12.0.92 (excluding)
cpe:2.3:o:intel:active_management_technology_firmware:*:*:*:*:*:*:*:* 14.1 (including) 14.1.67 (excluding)
cpe:2.3:o:intel:active_management_technology_firmware:*:*:*:*:*:*:*:* 15.0 (including) 15.0.42 (excluding)
cpe:2.3:o:intel:active_management_technology_firmware:*:*:*:*:*:*:*:* 16.1.0 (including) 16.1.25 (excluding)