cbcvebase.

Intel Active Management Technology Firmware vulnerabilities

49 known vulnerabilities affecting intel/active_management_technology_firmware.

Total CVEs
49
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL9HIGH19MEDIUM21

Vulnerabilities

Page 3 of 3
CVE-2020-8746P4MEDIUMCVSS 6.5fixed in 11.8.80≥ 11.12.0, < 11.12.80+3 more2020-11-12
CVE-2020-8746 [MEDIUM] CWE-190 CVE-2020-8746: Integer overflow in subsystem for Intel(R) AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 Integer overflow in subsystem for Intel(R) AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
nvd
CVE-2019-11086P4MEDIUMCVSS 6.8≥ 12.0, < 12.0.452019-12-18
CVE-2019-11086 [MEDIUM] CWE-20 CVE-2019-11086: Insufficient input validation in subsystem for Intel(R) AMT before version 12.0.45 may allow an unau Insufficient input validation in subsystem for Intel(R) AMT before version 12.0.45 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
nvd
CVE-2018-3629P4MEDIUMCVSS 6.5≥ 3.0, ≤ 11.22.702018-07-10
CVE-2018-3629 [MEDIUM] CWE-119 CVE-2018-3629: Buffer overflow in event handler in Intel Active Management Technology in Intel Converged Security M Buffer overflow in event handler in Intel Active Management Technology in Intel Converged Security Manageability Engine Firmware 3.x, 4.x, 5.x, 6.x, 7.x, 8.x, 9.x, 10.x, and 11.x may allow an attacker to cause a denial of service via the same subnet.
nvd
CVE-2020-0537P4MEDIUMCVSS 4.9≥ 11.0, < 11.8.77≥ 11.10, < 11.12.77+2 more2020-06-15
CVE-2020-0537 [MEDIUM] CWE-20 CVE-2020-0537: Improper input validation in subsystem for Intel(R) AMT versions before 11.8.77, 11.12.77, 11.22.77 Improper input validation in subsystem for Intel(R) AMT versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow a privileged user to potentially enable denial of service via network access.
nvd
CVE-2019-0097P4MEDIUMCVSS 4.9≥ 12.0.20, < 12.0.352019-05-17
CVE-2019-0097 [MEDIUM] CWE-20 CVE-2019-0097: Insufficient input validation vulnerability in subsystem for Intel(R) AMT before version 12.0.35 may Insufficient input validation vulnerability in subsystem for Intel(R) AMT before version 12.0.35 may allow a privileged user to potentially enable denial of service via network access.
nvd
CVE-2019-11100P4MEDIUMCVSS 4.6≥ 11.0, < 11.8.70≥ 11.10, < 11.11.70+2 more2019-12-18
CVE-2019-11100 [MEDIUM] CWE-20 CVE-2019-11100: Insufficient input validation in the subsystem for Intel(R) AMT before versions 11.8.70, 11.11.70, 1 Insufficient input validation in the subsystem for Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially enable information disclosure via physical access.
nvd
CVE-2019-0094P4MEDIUMCVSS 4.3≥ 11.8.0, < 11.8.65≥ 11.11.0, < 11.11.65+2 more2019-05-17
CVE-2019-0094 [MEDIUM] CWE-20 CVE-2019-0094: Insufficient input validation vulnerability in subsystem for Intel(R) AMT before versions 11.8.65, 1 Insufficient input validation vulnerability in subsystem for Intel(R) AMT before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 may allow an unauthenticated user to potentially enable denial of service via adjacent network access.
nvd
CVE-2020-12356P4MEDIUMCVSS 4.4fixed in 11.8.80≥ 11.12.0, < 11.12.80+3 more2020-11-12
CVE-2020-12356 [MEDIUM] CWE-125 CVE-2020-12356: Out-of-bounds read in subsystem in Intel(R) AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 Out-of-bounds read in subsystem in Intel(R) AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow a privileged user to potentially enable information disclosure via local access.
nvd
CVE-2017-5698P4MEDIUMCVSS 4.4v11.0.25.3001v11.0.26.30002017-09-05
CVE-2017-5698 [MEDIUM] CVE-2017-5698: Intel Active Management Technology, Intel Standard Manageability, and Intel Small Business Technolog Intel Active Management Technology, Intel Standard Manageability, and Intel Small Business Technology firmware versions 11.0.25.3001 and 11.0.26.3000 anti-rollback will not prevent upgrading to firmware version 11.6.x.1xxx which is vulnerable to CVE-2017-5689 and can be performed by a local user with administrative privileges.
nvd
Intel Active Management Technology Firmware vulnerabilities | cvebase