CVE-2022-38102Improper Input Validation in Intel Converged Security Management Engine Firmware

Severity
4.4MEDIUMNVD
CNA7.2
EPSS
0.0%
top 93.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 11

Description

Improper Input validation in firmware for some Intel(R) Converged Security and Management Engine before versions 15.0.45, and 16.1.27 may allow a privileged user to potentially enable denial of service via local access.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:HExploitability: 0.8 | Impact: 3.6

Affected Packages1 packages

🔴Vulnerability Details

2
CVEList
CVE-2022-38102: Improper Input validation in firmware for some Intel(R) Converged Security and Management Engine before versions 152023-08-11
GHSA
GHSA-hgxh-jg44-2849: Improper Input validation in firmware for some Intel(R) Converged Security and Management Engine before versions 152023-08-11
CVE-2022-38102 — Improper Input Validation in Intel | cvebase