CVE-2022-26074: Medium severity intel server platform services vulnerability
Published Aug 18, 2022
·Updated
Incomplete cleanup in a firmware subsystem for Intel(R) SPS before versions SPSE304.08.04.330.0 and SPSE304.01.04.530.0 may allow a privileged user to potentially enable denial of service via local access.
Affected Software
2 affected components
Intel Server Platform Services<sps_e3_04.01.04.530.0
Intel Server Platform Services>sps_e3_04.01.04.530.0<sps_e3_04.08.04.330.0
Event History
Aug 18, 2022
CVE Published
via MITRE·07:56 PM
Data Sourced
via MITRE·07:56 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-26074?
CVE-2022-26074 is a vulnerability in Intel(R) SPS firmware that allows a privileged user to potentially enable denial of service via local access.
2
What is the severity of CVE-2022-26074?
The severity of CVE-2022-26074 is medium with a CVSS score of 4.4.
3
How does CVE-2022-26074 affect Intel Server Platform Services Firmware?
CVE-2022-26074 affects Intel Server Platform Services Firmware versions SPS_E3_04.08.04.330.0 and SPS_E3_04.01.04.530.0.
4
How can this vulnerability be exploited?
This vulnerability can be exploited by a privileged user with local access to the system.
5
Are there any fixes or patches available for CVE-2022-26074?
Yes, Intel has provided fixes and patches for CVE-2022-26074. Please refer to the references for more information.