8.6

CVE-2022-36392

Improper input validation in some firmware for Intel(R) AMT and Intel(R) Standard Manageability before versions 11.8.94, 11.12.94, 11.22.94, 12.0.93, 14.1.70, 15.0.45, and 16.1.27 in Intel (R) CSME may allow an unauthenticated user to potentially enable denial of service via network access.

Data is provided by the National Vulnerability Database (NVD)
IntelConverged Security Management Engine Firmware Version < 11.12.94
   IntelC232 Version-
   IntelC236 Version-
   IntelC420 Version-
   IntelC422 Version-
   IntelCm236 Version-
   IntelCm238 Version-
   IntelX299 Version-
IntelConverged Security Management Engine Firmware Version < 11.8.94
   IntelB150 Version-
   IntelB250 Version-
   IntelCore I3-8100 Version-
   IntelCore I3-8100b Version-
   IntelCore I3-8100h Version-
   IntelCore I3-8100t Version-
   IntelCore I3-8109u Version-
   IntelCore I3-8130u Version-
   IntelCore I3-8140u Version-
   IntelCore I3-8145u Version-
   IntelCore I3-8145ue Version-
   IntelCore I3-8300 Version-
   IntelCore I3-8300t Version-
   IntelCore I3-8350k Version-
   IntelCore I5-8200y Version-
   IntelCore I5-8210y Version-
   IntelCore I5-8250u Version-
   IntelCore I5-8257u Version-
   IntelCore I5-8259u Version-
   IntelCore I5-8260u Version-
   IntelCore I5-8265u Version-
   IntelCore I5-8269u Version-
   IntelCore I5-8279u Version-
   IntelCore I5-8300h Version-
   IntelCore I5-8305g Version-
   IntelCore I5-8310y Version-
   IntelCore I5-8350u Version-
   IntelCore I5-8365u Version-
   IntelCore I5-8365ue Version-
   IntelCore I5-8400 Version-
   IntelCore I5-8400b Version-
   IntelCore I5-8400h Version-
   IntelCore I5-8400t Version-
   IntelCore I5-8500 Version-
   IntelCore I5-8500b Version-
   IntelCore I5-8500t Version-
   IntelCore I5-8600 Version-
   IntelCore I5-8600k Version-
   IntelCore I5-8600t Version-
   IntelCore I7+8700 Version-
   IntelCore I7-8086k Version-
   IntelCore I7-8500y Version-
   IntelCore I7-8550u Version-
   IntelCore I7-8557u Version-
   IntelCore I7-8559u Version-
   IntelCore I7-8565u Version-
   IntelCore I7-8569u Version-
   IntelCore I7-8650u Version-
   IntelCore I7-8665u Version-
   IntelCore I7-8665ue Version-
   IntelCore I7-8700 Version-
   IntelCore I7-8700b Version-
   IntelCore I7-8700k Version-
   IntelCore I7-8700t Version-
   IntelCore I7-8705g Version-
   IntelCore I7-8706g Version-
   IntelCore I7-8709g Version-
   IntelCore I7-8750h Version-
   IntelCore I7-8809g Version-
   IntelCore I7-8850h Version-
   IntelCore I9-8950hk Version-
   IntelCore M3-8100y Version-
   IntelH110 Version-
   IntelH170 Version-
   IntelH270 Version-
   IntelHm170 Version-
   IntelHm175 Version-
   IntelQ150 Version-
   IntelQ170 Version-
   IntelQ250 Version-
   IntelQ270 Version-
   IntelQm170 Version-
   IntelQm175 Version-
   IntelX299 Version-
   IntelZ170 Version-
   IntelZ270 Version-
IntelConverged Security Management Engine Firmware Version < 12.0.93
   IntelB360 Version-
   IntelB365 Version-
   IntelC242 Version-
   IntelC246 Version-
   IntelCeleron 4205u Version-
   IntelCeleron 4305u Version-
   IntelCeleron 4305ue Version-
   IntelCm246 Version-
   IntelCore I3-8100 Version-
   IntelCore I3-8100b Version-
   IntelCore I3-8100h Version-
   IntelCore I3-8100t Version-
   IntelCore I3-8109u Version-
   IntelCore I3-8130u Version-
   IntelCore I3-8140u Version-
   IntelCore I3-8145u Version-
   IntelCore I3-8145ue Version-
   IntelCore I3-8300 Version-
   IntelCore I3-8300t Version-
   IntelCore I3-8350k Version-
   IntelCore I5-8200y Version-
   IntelCore I5-8210y Version-
   IntelCore I5-8250u Version-
   IntelCore I5-8257u Version-
   IntelCore I5-8259u Version-
   IntelCore I5-8260u Version-
   IntelCore I5-8265u Version-
   IntelCore I5-8269u Version-
   IntelCore I5-8279u Version-
   IntelCore I5-8300h Version-
   IntelCore I5-8305g Version-
   IntelCore I5-8310y Version-
   IntelCore I5-8350u Version-
   IntelCore I5-8365u Version-
   IntelCore I5-8365ue Version-
   IntelCore I5-8400 Version-
   IntelCore I5-8400b Version-
   IntelCore I5-8400h Version-
   IntelCore I5-8400t Version-
   IntelCore I5-8500 Version-
   IntelCore I5-8500b Version-
   IntelCore I5-8500t Version-
   IntelCore I5-8600 Version-
   IntelCore I5-8600k Version-
   IntelCore I5-8600t Version-
   IntelCore I7+8700 Version-
   IntelCore I7-8086k Version-
   IntelCore I7-8500y Version-
   IntelCore I7-8550u Version-
   IntelCore I7-8557u Version-
   IntelCore I7-8559u Version-
   IntelCore I7-8565u Version-
   IntelCore I7-8569u Version-
   IntelCore I7-8650u Version-
   IntelCore I7-8665u Version-
   IntelCore I7-8665ue Version-
   IntelCore I7-8700 Version-
   IntelCore I7-8700b Version-
   IntelCore I7-8700k Version-
   IntelCore I7-8700t Version-
   IntelCore I7-8705g Version-
   IntelCore I7-8706g Version-
   IntelCore I7-8709g Version-
   IntelCore I7-8750h Version-
   IntelCore I7-8809g Version-
   IntelCore I7-8850h Version-
   IntelCore I9-8950hk Version-
   IntelCore M3-8100y Version-
   IntelH310 Version-
   IntelH370 Version-
   IntelHm370 Version-
   IntelPentium Gold 5405u Version-
   IntelQ370 Version-
   IntelQm370 Version-
   IntelZ370 Version-
   IntelZ390 Version-
IntelConverged Security Management Engine Firmware Version < 14.1.70
   IntelB460 Version-
   IntelH410 Version-
   IntelH420e Version-
   IntelH470 Version-
   IntelHm470 Version-
   IntelQ470 Version-
   IntelQ470e Version-
   IntelQm480 Version-
   IntelW480 Version-
   IntelW480e Version-
   IntelWm490 Version-
   IntelZ490 Version-
IntelConverged Security Management Engine Firmware Version >= 14.5.0 < 14.5.50
   IntelB460 Version-
   IntelH410 Version-
   IntelH420e Version-
   IntelH470 Version-
   IntelHm470 Version-
   IntelQ470 Version-
   IntelQ470e Version-
   IntelQm480 Version-
   IntelW480 Version-
   IntelW480e Version-
   IntelWm490 Version-
   IntelZ490 Version-
IntelConverged Security Management Engine Firmware Version < 15.0.45
   IntelB560 Version-
   IntelH510 Version-
   IntelH570 Version-
   IntelHm570 Version-
   IntelHm570e Version-
   IntelQ570 Version-
   IntelQm580 Version-
   IntelQm580e Version-
   IntelRm590e Version-
   IntelW580 Version-
   IntelWm590 Version-
   IntelZ590 Version-
IntelConverged Security Management Engine Firmware Version < 16.1.27
   IntelB660 Version-
   IntelH610 Version-
   IntelH610e Version-
   IntelH670 Version-
   IntelHm670 Version-
   IntelQ670 Version-
   IntelQ670e Version-
   IntelR680e Version-
   IntelW680 Version-
   IntelWm690 Version-
   IntelZ690 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.11% 0.269
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
secure@intel.com 8.6 3.9 4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
CWE-116 Improper Encoding or Escaping of Output

The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.