First published: Fri Aug 11 2023(Updated: )
Cross-site Scripting (XSS) in some Intel(R) Manageability Commander software before version 2.3 may allow an unauthenticated user to potentially enable escalation of privilege via network access.
Credit: secure@intel.com secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel Manageability Commander | <2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this cross-site scripting (XSS) vulnerability is CVE-2022-29887.
The severity of CVE-2022-29887 is critical with a CVSS score of 9.6.
Some versions of Intel(R) Manageability Commander software before version 2.3 are affected by CVE-2022-29887.
An unauthenticated user can potentially exploit CVE-2022-29887 via network access, enabling escalation of privilege.
More information about CVE-2022-29887 can be found on the Intel Security Center Advisory page: http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00893.html