Active Management Technology Firmware
Vendor:
First CVE: May 2, 2017 · Active for 9 years
54
Total CVEs
More Total CVEs than 98% of tracked products
10.8
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 48% of tracked products
1.9%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Active Management Technology Firmware over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 2, 2017
9 years ago
Most Recent CVE
Nov 11, 2022
1,351 days ago
CVE Severity & Scoring
Active Management Technology Firmware54 CVEs
43%
39%
19%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local9 (16.7%)
Network32 (59.3%)
Unknown0 (0.0%)
Physical4 (7.4%)
Adjacent Network9 (16.7%)
Attack Complexity
Low52 (96.3%)
High2 (3.7%)
Unknown0 (0.0%)
User Interaction
None52 (96.3%)
Unknown0 (0.0%)
Required2 (3.7%)
Privileges Required
Low7 (13.0%)
High10 (18.5%)
None37 (68.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (54 CVEs).
54 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-5689CRITICAL An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (IS | May 2, 2017 | 9.8 | 99 | YES | YES |
CVE-2022-26845CRITICAL Improper authentication in firmware for Intel(R) AMT before versions 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 may allow an unauthenticated user to potentiall | Nov 11, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-30601CRITICAL Insufficiently protected credentials for Intel(R) AMT and Intel(R) Standard Manageability may allow an unauthenticated user to potentially enable information disclosure and escalat | Aug 18, 2022 | 9.8 | 31 | NO | NO |
CVE-2020-8752CRITICAL Out-of-bounds write in IPv6 subsystem for Intel(R) AMT, Intel(R) ISM versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 14.0.45 may allow an unauthenticated user to potentially | Nov 12, 2020 | 9.8 | 31 | NO | NO |
CVE-2020-8758CRITICAL Improper buffer restrictions in network subsystem in provisioned Intel(R) AMT and Intel(R) ISM versions before 11.8.79, 11.12.79, 11.22.79, 12.0.68 and 14.0.39 may allow an unauthe | Sep 10, 2020 | 9.8 | 31 | NO | NO |
CVE-2020-0594CRITICAL Out-of-bounds read in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enabl | Jun 15, 2020 | 9.8 | 31 | NO | NO |
CVE-2019-11131CRITICAL Logic issue in subsystem in Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially enable escalation of privilege via | Dec 18, 2019 | 9.8 | 30 | NO | NO |
CVE-2019-11107CRITICAL Insufficient input validation in the subsystem for Intel(R) AMT before version 12.0.45 may allow an unauthenticated user to potentially enable escalation of privilege via network a | Dec 18, 2019 | 9.8 | 29 | NO | NO |
CVE-2020-8749HIGH Out-of-bounds read in subsystem for Intel(R) AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow an unauthenticated user to potentially enable escalation | Nov 12, 2020 | 8.8 | 28 | NO | NO |
CVE-2020-8747CRITICAL Out-of-bounds read in subsystem for Intel(R) AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow an unauthenticated user to potentially enable informatio | Nov 12, 2020 | 9.1 | 28 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (54 CVEs).
CISA KEV
1 CVE
1.9% of CVEs· 96th percentile
Metasploit
1 CVE
1.9% of CVEs· 96th percentile
Nuclei
1 CVE
1.9% of CVEs· 96th percentile
ExploitDB
1 CVE
1.9% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (54 CVEs).
Media Mentions
Signals from CVEs in this product scope (54 CVEs).
Top CNAs Publishing CVEs For Active Management Technology Firmware
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.5 | 1 | 9.8 | 92.2% | 1 | 1 |
| 9.1 | 1 | 9.8 | 92.2% | 1 | 1 |
| 9.0 | 1 | 9.8 | 92.2% | 1 | 1 |
| 8.1 | 1 | 9.8 | 92.2% | 1 | 1 |
| 8.0 | 1 | 9.8 | 92.2% | 1 | 1 |
| 7.1 | 1 | 9.8 | 92.2% | 1 | 1 |
| 7.0 | 1 | 9.8 | 92.2% | 1 | 1 |
| 6.2 | 1 | 9.8 | 92.2% | 1 | 1 |
| 6.1 | 1 | 9.8 | 92.2% | 1 | 1 |
| 6.0 | 1 | 9.8 | 92.2% | 1 | 1 |
| 11.6 | 1 | 9.8 | 92.2% | 1 | 1 |
| 11.5 | 1 | 9.8 | 92.2% | 1 | 1 |
| 11.0.26.3000 | 1 | 4.4 | 0.3% | 0 | 0 |
| 11.0.25.3001 | 1 | 4.4 | 0.3% | 0 | 0 |
| 11.0 | 1 | 9.8 | 92.2% | 1 | 1 |
| 10.0 | 1 | 9.8 | 92.2% | 1 | 1 |