CVE-2022-21225 is an improper neutralization vulnerability in Intel Data Center Manager software versions prior to 4.1, allowing an authenticated user with adjacent network access to potentially escalate privileges. This high-severity vulnerability (CVSS 8.0) has a low attack complexity and can lead to high impacts on confidentiality, integrity, and availability. While there is no known active exploitation in the wild or public exploit code (Metasploit, Nuclei, ExploitDB), it has garnered community attention, including a Reddit post detailing a path from SQL Injection to RCE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.1CPE matchmatch criteria | cpe:2.3:a:intel:data_center_manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.