Improper access control in Intel Active Management Technology and Standard Manageability (ISM) - CVE-2022-28697
Published: August 11, 2022
Vulnerability identifier: #VU66398
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-28697
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in firmware. An attacker with physical access can bypass implemented security restrictions and gain elevated privileges on the system.
Affected software
Intel Active Management Technology
Standard Manageability (ISM)
Standard Manageability (ISM)
How to mitigate CVE-2022-28697
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.