CVE Vulnerabilities

CVE-2022-26341

Insufficiently Protected Credentials

Published: Nov 11, 2022 | Modified: Feb 05, 2025
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Insufficiently protected credentials in software in Intel(R) AMT SDK before version 16.0.4.1, Intel(R) EMA before version 1.7.1 and Intel(R) MC before version 2.3.2 may allow an authenticated user to potentially enable escalation of privilege via network access.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

NameVendorStart VersionEnd Version
Active_management_technology_software_development_kitIntel*16.0.4.1 (excluding)
Endpoint_management_assistantIntel*1.7.1 (excluding)
Manageability_commanderIntel*2.3.2 (excluding)

Potential Mitigations

References