CVE Vulnerabilities

CVE-2022-27497

NULL Pointer Dereference

Published: Nov 11, 2022 | Modified: Feb 05, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Null pointer dereference in firmware for Intel(R) AMT before version 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 may allow an unauthenticated user to potentially enable denial of service via network access.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
Active_management_technology_firmwareIntel*11.8.93 (excluding)
Active_management_technology_firmwareIntel11.12.0 (including)11.12.93 (excluding)
Active_management_technology_firmwareIntel11.22.0 (including)11.22.93 (excluding)
Active_management_technology_firmwareIntel12.0 (including)12.0.92 (excluding)
Active_management_technology_firmwareIntel14.1 (including)14.1.67 (excluding)
Active_management_technology_firmwareIntel15.0 (including)15.0.42 (excluding)
Active_management_technology_firmwareIntel16.1.0 (including)16.1.25 (excluding)

Potential Mitigations

References