Intel
Intel Active Management Technology Firmware: vulnerabilidades y CVE
Intel Active Management Technology Firmware tiene 54 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 10 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE54
Últimos 12 meses0
Críticas10
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2017-5689 | Crítica (9.8) | 92% | ⚠ Explotación activa | 2 may 2017 | An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM). An unprivileged local attacker… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-29893 | Alta (8.8) | 0.61% | — | 11 nov 2022 | Improper authentication in firmware for Intel(R) AMT before versions 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 may allow an authenticated user to potentially enable escalation of privilege via… |
| CVE-2022-27497 | Alta (7.5) | 0.70% | — | 11 nov 2022 | Null pointer dereference in firmware for Intel(R) AMT before version 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 may allow an unauthenticated user to potentially enable denial of service via network… |
| CVE-2022-26845 | Crítica (9.8) | 0.60% | — | 11 nov 2022 | Improper authentication in firmware for Intel(R) AMT before versions 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 may allow an unauthenticated user to potentially enable escalation of privilege via… |
| CVE-2021-33159 | Media (6.7) | 0.18% | — | 11 nov 2022 | Improper authentication in subsystem for Intel(R) AMT before versions 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 may allow a privileged user to potentially enable escalation of privilege via local… |
| CVE-2022-30944 | Media (5.5) | 0.19% | — | 18 ago 2022 | Insufficiently protected credentials for Intel(R) AMT and Intel(R) Standard Manageability may allow a privileged user to potentially enable information disclosure via local access. |
| CVE-2022-30601 | Crítica (9.8) | 0.88% | — | 18 ago 2022 | Insufficiently protected credentials for Intel(R) AMT and Intel(R) Standard Manageability may allow an unauthenticated user to potentially enable information disclosure and escalation of privilege via network access. |
| CVE-2022-28697 | Media (6.8) | 0.37% | — | 18 ago 2022 | Improper access control in firmware for Intel(R) AMT and Intel(R) Standard Manageability may allow an unauthenticated user to potentially enable escalation of privilege via physical access. |
| CVE-2021-33068 | Media (6.5) | 0.84% | — | 9 feb 2022 | Null pointer dereference in subsystem for Intel(R) AMT before versions 15.0.35 may allow an authenticated user to potentially enable denial of service via network access. |
| CVE-2020-8760 | Alta (7.8) | 0.42% | — | 12 nov 2020 | Integer overflow in subsystem for Intel(R) AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 14.0.45 may allow a privileged user to potentially enable escalation of privilege via local access. |
| CVE-2020-8757 | Media (6.7) | 0.42% | — | 12 nov 2020 | Out-of-bounds read in subsystem for Intel(R) AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow a privileged user to potentially enable escalation of privilege via local access. |
| CVE-2020-8754 | Alta (7.5) | 1.5% | — | 12 nov 2020 | Out-of-bounds read in subsystem for Intel(R) AMT, Intel(R) ISM versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow an unauthenticated user to potentially enable information disclosure via network… |
| CVE-2020-8753 | Alta (7.5) | 1.5% | — | 12 nov 2020 | Out-of-bounds read in DHCP subsystem for Intel(R) AMT, Intel(R) ISM versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow an unauthenticated user to potentially enable information disclosure via… |
| CVE-2020-8752 | Crítica (9.8) | 1.7% | — | 12 nov 2020 | Out-of-bounds write in IPv6 subsystem for Intel(R) AMT, Intel(R) ISM versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 14.0.45 may allow an unauthenticated user to potentially enable escalation of privileges via… |
| CVE-2020-8749 | Alta (8.8) | 1.1% | — | 12 nov 2020 | Out-of-bounds read in subsystem for Intel(R) AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access. |
| CVE-2020-8747 | Crítica (9.1) | 1.7% | — | 12 nov 2020 | Out-of-bounds read in subsystem for Intel(R) AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow an unauthenticated user to potentially enable information disclosure and/or denial of service… |
| CVE-2020-8746 | Media (6.5) | 0.88% | — | 12 nov 2020 | Integer overflow in subsystem for Intel(R) AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow an unauthenticated user to potentially enable denial of service via adjacent access. |
| CVE-2020-12356 | Media (4.4) | 0.39% | — | 12 nov 2020 | Out-of-bounds read in subsystem in Intel(R) AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow a privileged user to potentially enable information disclosure via local access. |
| CVE-2020-8758 | Crítica (9.8) | 1.9% | — | 10 sept 2020 | Improper buffer restrictions in network subsystem in provisioned Intel(R) AMT and Intel(R) ISM versions before 11.8.79, 11.12.79, 11.22.79, 12.0.68 and 14.0.39 may allow an unauthenticated user to potentially enable… |
| CVE-2020-8674 | Media (5.3) | 1.8% | — | 15 jun 2020 | Out-of-bounds read in DHCPv6 subsystem in Intel(R) AMT and Intel(R)ISM versions before 11.8.77, 11.12.77, 11.22.77, 12.0.64 and 14.0.33 may allow an unauthenticated user to potentially enable information disclosure via… |
| CVE-2020-0597 | Alta (7.5) | 3.0% | — | 15 jun 2020 | Out-of-bounds read in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 14.0.33 may allow an unauthenticated user to potentially enable denial of service via network access. |
| CVE-2020-0596 | Alta (7.5) | 2.2% | — | 15 jun 2020 | Improper input validation in DHCPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable information disclosure via… |
| CVE-2020-0595 | Crítica (9.8) | 3.4% | — | 15 jun 2020 | Use after free in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable escalation of privilege via network… |
| CVE-2020-0594 | Crítica (9.8) | 3.5% | — | 15 jun 2020 | Out-of-bounds read in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable escalation of privilege via network… |
| CVE-2020-0540 | Alta (7.5) | 2.0% | — | 15 jun 2020 | Insufficiently protected credentials in Intel(R) AMT versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable information disclosure via network access. |
| CVE-2020-0538 | Alta (7.5) | 2.3% | — | 15 jun 2020 | Improper input validation in subsystem for Intel(R) AMT versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable denial of service via network access. |
| CVE-2020-0537 | Media (4.9) | 1.6% | — | 15 jun 2020 | Improper input validation in subsystem for Intel(R) AMT versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow a privileged user to potentially enable denial of service via network access. |
| CVE-2020-0535 | Media (5.3) | 1.6% | — | 15 jun 2020 | Improper input validation in Intel(R) AMT versions before 11.8.76, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable information disclosure via network access. |
| CVE-2020-0532 | Alta (7.1) | 0.67% | — | 15 jun 2020 | Improper input validation in subsystem for Intel(R) AMT versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable denial of service or information disclosure via… |
| CVE-2020-0531 | Media (6.5) | 1.4% | — | 15 jun 2020 | Improper input validation in Intel(R) AMT versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an authenticated user to potentially enable information disclosure via network access. |
| CVE-2019-11132 | Alta (8.4) | 1.3% | — | 18 dic 2019 | Cross site scripting in subsystem in Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow a privileged user to potentially enable escalation of privilege via network access. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Intel
Graphics Driver · 73Proset/wireless Wifi · 52Converged Security Management Engine Firmware · 44Quartus Prime · 44Core I7-10710u Firmware · 43Graphics Drivers · 43Core I9-9900k Firmware · 42Core I7-10510u Firmware · 42Core I7-8665u Firmware · 42Core I7-10510y Firmware · 42Core I7-8565u Firmware · 41Core I7-8650u Firmware · 41