CVE-2022-27497: Null Pointer Dereference
Null pointer dereference in firmware for Intel(R) AMT before version 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 may allow an unauthenticated user to potentially enable denial of service via network access.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-27497?
CVE-2022-27497 is a vulnerability in the firmware for Intel(R) Active Management Technology (AMT) that may allow an unauthenticated user to potentially enable denial of service via network access.
How does CVE-2022-27497 affect Intel AMT firmware?
CVE-2022-27497 affects Intel AMT firmware versions before 11.8.93, 11.12.93, 11.22.93, 12.0.92, 14.1.67, 15.0.42, and 16.1.25.
What is the severity of CVE-2022-27497?
The severity of CVE-2022-27497 is rated as high with a CVSS score of 7.5.
How can an unauthenticated user exploit CVE-2022-27497?
An unauthenticated user can potentially enable denial of service via network access exploiting CVE-2022-27497.
How can I mitigate CVE-2022-27497?
To mitigate CVE-2022-27497, update the Intel AMT firmware to version 11.8.93 or later.