#VU66398 Improper access control in Intel Active Management Technology and Standard Manageability (ISM) - CVE-2022-28697
Published: August 11, 2022
Vulnerability identifier: #VU66398
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2022-28697
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
Intel Active Management Technology
Standard Manageability (ISM)
Intel Active Management Technology
Standard Manageability (ISM)
Software vendor:
Intel
Intel
Description
The vulnerability allows a local attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in firmware. An attacker with physical access can bypass implemented security restrictions and gain elevated privileges on the system.
Remediation
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.