CVE Vulnerabilities

CVE-2022-27497

NULL Pointer Dereference

Published: Nov 11, 2022 | Modified: May 22, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Null pointer dereference in firmware for Intel(R) AMT before version 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 may allow an unauthenticated user to potentially enable denial of service via network access.

Weakness

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

Affected Software

Name Vendor Start Version End Version
Active_management_technology_firmware Intel * 11.8.93 (excluding)
Active_management_technology_firmware Intel 11.12.0 (including) 11.12.93 (excluding)
Active_management_technology_firmware Intel 11.22.0 (including) 11.22.93 (excluding)
Active_management_technology_firmware Intel 12.0 (including) 12.0.92 (excluding)
Active_management_technology_firmware Intel 14.1 (including) 14.1.67 (excluding)
Active_management_technology_firmware Intel 15.0 (including) 15.0.42 (excluding)
Active_management_technology_firmware Intel 16.1.0 (including) 16.1.25 (excluding)

Potential Mitigations

References