CVE-2022-29893 is an improper authentication vulnerability affecting Intel Active Management Technology (AMT) firmware versions before 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.0.42, and 16.1.25. This flaw carries a high CVSS score of 8.8, indicating that an authenticated attacker with network access could exploit it to achieve escalation of privilege, leading to high impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation, public exploit code, or KEV listing, the vulnerability has garnered some community discussion and media coverage, suggesting awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 11.8.93CPE matchmatch criteria | cpe:2.3:o:intel:active_management_technology_firmware:*:*:*:*:*:*:*:* | ||
>= 11.12.0, < 11.12.93CPE matchmatch criteria | cpe:2.3:o:intel:active_management_technology_firmware:*:*:*:*:*:*:*:* | ||
>= 11.22.0, < 11.22.93CPE matchmatch criteria | cpe:2.3:o:intel:active_management_technology_firmware:*:*:*:*:*:*:*:* | ||
>= 12.0, < 12.0.92CPE matchmatch criteria | cpe:2.3:o:intel:active_management_technology_firmware:*:*:*:*:*:*:*:* | ||
>= 14.1, < 14.1.67CPE matchmatch criteria | cpe:2.3:o:intel:active_management_technology_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.