#VU66398 Improper access control in Intel Active Management Technology and Standard Manageability (ISM)


Published: 2022-08-11

Vulnerability identifier: #VU66398

Vulnerability risk: Low

CVSSv3.1: 6.4 [CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N/E:U/RL:U/RC:C]

CVE-ID: CVE-2022-28697

CWE-ID: CWE-284

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Intel Active Management Technology
Hardware solutions / Firmware
Standard Manageability (ISM)
Hardware solutions / Security hardware applicances

Vendor: Intel

Description

The vulnerability allows a local attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions in firmware. An attacker with physical access can bypass implemented security restrictions and gain elevated privileges on the system.

Mitigation
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

Vulnerable software versions

Intel Active Management Technology: All versions

Standard Manageability (ISM): All versions


External links
http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00709.html


Q & A

Can this vulnerability be exploited remotely?

No. The attacker should have physical access to the system in order to successfully exploit this vulnerability.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability