cbcvebase.

Intel Active Management Technology Firmware vulnerabilities

49 known vulnerabilities affecting intel/active_management_technology_firmware.

Total CVEs
49
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL9HIGH19MEDIUM21

Vulnerabilities

Page 2 of 3
CVE-2019-0096P3HIGHCVSS 8.0≥ 11.8.0, < 11.8.65≥ 11.11.0, < 11.11.65+2 more2019-05-17
CVE-2019-0096 [HIGH] CWE-787 CVE-2019-0096: Out of bound write vulnerability in subsystem for Intel(R) AMT before versions 11.8.65, 11.11.65, 11 Out of bound write vulnerability in subsystem for Intel(R) AMT before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 may allow an authenticated user to potentially enable escalation of privilege via adjacent network access.
nvd
CVE-2022-27497P3HIGHCVSS 7.5fixed in 11.8.93≥ 11.12.0, < 11.12.93+5 more2022-11-11
CVE-2022-27497 [HIGH] CWE-476 CVE-2022-27497: Null pointer dereference in firmware for Intel(R) AMT before version 11.8.93, 11.22.93, 11.12.93, 12 Null pointer dereference in firmware for Intel(R) AMT before version 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 may allow an unauthenticated user to potentially enable denial of service via network access.
nvd
CVE-2020-8760P3HIGHCVSS 7.8fixed in 11.8.80≥ 11.12.0, < 11.12.80+3 more2020-11-12
CVE-2020-8760 [HIGH] CWE-190 CVE-2020-8760: Integer overflow in subsystem for Intel(R) AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, Integer overflow in subsystem for Intel(R) AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 14.0.45 may allow a privileged user to potentially enable escalation of privilege via local access.
nvd
CVE-2018-12187P3HIGHCVSS 7.5≥ 11.0, < 11.8.60≥ 11.10, < 11.11.60+2 more2019-03-14
CVE-2018-12187 [HIGH] CWE-20 CVE-2018-12187: Insufficient input validation in Intel(R) Active Management Technology (Intel(R) AMT) before version Insufficient input validation in Intel(R) Active Management Technology (Intel(R) AMT) before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20 may allow an unauthenticated user to potentially cause a denial of service via network access.
nvd
CVE-2019-11132P3HIGHCVSS 8.4≥ 11.0, < 11.8.70≥ 11.10, < 11.11.70+2 more2019-12-18
CVE-2019-11132 [HIGH] CWE-79 CVE-2019-11132: Cross site scripting in subsystem in Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12 Cross site scripting in subsystem in Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow a privileged user to potentially enable escalation of privilege via network access.
nvd
CVE-2019-0131P3HIGHCVSS 8.1≥ 11.0, < 11.8.70≥ 11.10, < 11.11.70+2 more2019-12-18
CVE-2019-0131 [HIGH] CWE-20 CVE-2019-0131: Insufficient input validation in subsystem in Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22. Insufficient input validation in subsystem in Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially enable denial of service or information disclosure via adjacent access.
nvd
CVE-2017-5729P3HIGHCVSS 7.4≥ 11.0, ≤ 11.8.50.34202017-11-21
CVE-2017-5729 [HIGH] CVE-2017-5729: Frame replay vulnerability in Wi-Fi subsystem in Intel Dual-Band and Tri-Band Wireless-AC Products a Frame replay vulnerability in Wi-Fi subsystem in Intel Dual-Band and Tri-Band Wireless-AC Products allows remote attacker to replay frames via channel-based man-in-the-middle.
nvd
CVE-2020-0531P4MEDIUMCVSS 6.5≥ 11.0, < 11.8.77≥ 11.10, < 11.12.77+2 more2020-06-15
CVE-2020-0531 [MEDIUM] CWE-20 CVE-2020-0531: Improper input validation in Intel(R) AMT versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 ma Improper input validation in Intel(R) AMT versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an authenticated user to potentially enable information disclosure via network access.
nvd
CVE-2018-3616P4MEDIUMCVSS 5.9fixed in 12.0.52018-09-12
CVE-2018-3616 [MEDIUM] CVE-2018-3616: Bleichenbacher-style side channel vulnerability in TLS implementation in Intel Active Management Tec Bleichenbacher-style side channel vulnerability in TLS implementation in Intel Active Management Technology before 12.0.5 may allow an unauthenticated user to potentially obtain the TLS session key via the network.
nvd
CVE-2020-8674P4MEDIUMCVSS 5.3≥ 11.0, < 11.8.77≥ 11.10, < 11.12.77+3 more2020-06-15
CVE-2020-8674 [MEDIUM] CWE-125 CVE-2020-8674: Out-of-bounds read in DHCPv6 subsystem in Intel(R) AMT and Intel(R)ISM versions before 11.8.77, 11.1 Out-of-bounds read in DHCPv6 subsystem in Intel(R) AMT and Intel(R)ISM versions before 11.8.77, 11.12.77, 11.22.77, 12.0.64 and 14.0.33 may allow an unauthenticated user to potentially enable information disclosure via network access.
nvd
CVE-2018-3657P4MEDIUMCVSS 6.7fixed in 12.0.52018-09-12
CVE-2018-3657 [MEDIUM] CWE-119 CVE-2018-3657: Multiple buffer overflows in Intel AMT in Intel CSME firmware versions before version 12.0.5 may all Multiple buffer overflows in Intel AMT in Intel CSME firmware versions before version 12.0.5 may allow a privileged user to potentially execute arbitrary code with Intel AMT execution privilege via local access.
nvd
CVE-2018-3658P4MEDIUMCVSS 5.3fixed in 12.0.52018-09-12
CVE-2018-3658 [MEDIUM] CWE-772 CVE-2018-3658: Multiple memory leaks in Intel AMT in Intel CSME firmware versions before 12.0.5 may allow an unauth Multiple memory leaks in Intel AMT in Intel CSME firmware versions before 12.0.5 may allow an unauthenticated user with Intel AMT provisioned to potentially cause a partial denial of service via network access.
nvd
CVE-2020-0535P4MEDIUMCVSS 5.3≥ 11.0, < 11.8.77≥ 11.10, < 11.12.77+2 more2020-06-15
CVE-2020-0535 [MEDIUM] CWE-20 CVE-2020-0535: Improper input validation in Intel(R) AMT versions before 11.8.76, 11.12.77, 11.22.77 and 12.0.64 ma Improper input validation in Intel(R) AMT versions before 11.8.76, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable information disclosure via network access.
nvd
CVE-2020-0532P4HIGHCVSS 7.1≥ 11.0, < 11.8.77≥ 11.10, < 11.12.77+2 more2020-06-15
CVE-2020-0532 [HIGH] CWE-20 CVE-2020-0532: Improper input validation in subsystem for Intel(R) AMT versions before 11.8.77, 11.12.77, 11.22.77 Improper input validation in subsystem for Intel(R) AMT versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable denial of service or information disclosure via adjacent access.
nvd
CVE-2018-3632P4MEDIUMCVSS 6.7≥ 6.0, ≤ 11.202018-07-10
CVE-2018-3632 [MEDIUM] CWE-787 CVE-2018-3632: Memory corruption in Intel Active Management Technology in Intel Converged Security Manageability En Memory corruption in Intel Active Management Technology in Intel Converged Security Manageability Engine Firmware 6.x / 7.x / 8.x / 9.x / 10.x / 11.0 / 11.5 / 11.6 / 11.7 / 11.10 / 11.20 could be triggered by an attacker with local administrator permission on the system.
nvd
CVE-2017-5697P4MEDIUMCVSS 6.5≥ 9.1, < 9.1.40.1000≥ 9.5, < 9.5.60.1952+3 more2017-06-14
CVE-2017-5697 [MEDIUM] CWE-1021 CVE-2017-5697: Insufficient clickjacking protection in the Web User Interface of Intel AMT firmware versions before Insufficient clickjacking protection in the Web User Interface of Intel AMT firmware versions before 9.1.40.1000, 9.5.60.1952, 10.0.50.1004, 11.0.0.1205, and 11.6.25.1129 potentially allowing a remote attacker to hijack users web clicks via attacker's crafted web page.
nvd
CVE-2021-33068P4MEDIUMCVSS 6.5fixed in 15.0.352022-02-09
CVE-2021-33068 [MEDIUM] CWE-476 CVE-2021-33068: Null pointer dereference in subsystem for Intel(R) AMT before versions 15.0.35 may allow an authenti Null pointer dereference in subsystem for Intel(R) AMT before versions 15.0.35 may allow an authenticated user to potentially enable denial of service via network access.
nvd
CVE-2020-8757P4MEDIUMCVSS 6.7fixed in 11.8.80≥ 11.12.0, < 11.12.80+3 more2020-11-12
CVE-2020-8757 [MEDIUM] CWE-125 CVE-2020-8757: Out-of-bounds read in subsystem for Intel(R) AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.7 Out-of-bounds read in subsystem for Intel(R) AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow a privileged user to potentially enable escalation of privilege via local access.
nvd
CVE-2021-33159P4MEDIUMCVSS 6.7fixed in 11.8.93≥ 11.12.0, < 11.12.93+5 more2022-11-11
CVE-2021-33159 [MEDIUM] CWE-287 CVE-2021-33159: Improper authentication in subsystem for Intel(R) AMT before versions 11.8.93, 11.22.93, 11.12.93, 1 Improper authentication in subsystem for Intel(R) AMT before versions 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 may allow a privileged user to potentially enable escalation of privilege via local access.
nvd
CVE-2019-0092P4MEDIUMCVSS 6.8≥ 11.8.0, < 11.8.65≥ 11.11.0, < 11.11.65+2 more2019-05-17
CVE-2019-0092 [MEDIUM] CWE-20 CVE-2019-0092: Insufficient input validation vulnerability in subsystem for Intel(R) AMT before versions 11.8.65, 1 Insufficient input validation vulnerability in subsystem for Intel(R) AMT before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
nvd