First published: Fri May 17 2019(Updated: )
Insufficient input validation vulnerability in subsystem for Intel(R) AMT before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 may allow an unauthenticated user to potentially enable denial of service via adjacent network access.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel Active Management Technology Firmware | >=11.8.0<11.8.65 | |
Intel Active Management Technology Firmware | >=11.11.0<11.11.65 | |
Intel Active Management Technology Firmware | >=11.22.0<11.22.65 | |
Intel Active Management Technology Firmware | >=12.0<12.0.35 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-0094 is an insufficient input validation vulnerability in the subsystem for Intel(R) AMT before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35, which may allow an unauthenticated user to potentially enable denial of service via adjacent network access.
The severity of CVE-2019-0094 is medium with a CVSS score of 4.3.
CVE-2019-0094 affects Intel Active Management Technology Firmware versions 11.8.x to 11.8.65, 11.11.x to 11.11.65, 11.22.x to 11.22.65, and 12.0.x to 12.0.35.
An unauthenticated user can potentially exploit CVE-2019-0094 by using adjacent network access to enable denial of service.
Yes, it is recommended to upgrade to the latest versions of Intel Active Management Technology Firmware to mitigate the vulnerability.