Vulnerabilities > Intel > High

DATE CVE VULNERABILITY TITLE RISK
2022-11-11 CVE-2022-26124 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Intel products
Improper buffer restrictions in BIOS firmware for some Intel(R) NUC Boards, Intel(R) NUC 8 Boards, Intel(R) NUC 8 Rugged Boards and Intel(R) NUC 8 Rugged Kits before version CHAPLCEL.0059 may allow a privileged user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-119
7.8
2022-11-11 CVE-2022-26341 Insufficiently Protected Credentials vulnerability in Intel products
Insufficiently protected credentials in software in Intel(R) AMT SDK before version 16.0.4.1, Intel(R) EMA before version 1.7.1 and Intel(R) MC before version 2.3.2 may allow an authenticated user to potentially enable escalation of privilege via network access.
network
low complexity
intel CWE-522
8.8
2022-11-11 CVE-2022-26367 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Intel XMM 7560 Firmware
Improper buffer restrictions in some Intel(R) XMM(TM) 7560 Modem software before version M2_7560_R_01.2146.00 may allow a privileged user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-119
8.2
2022-11-11 CVE-2022-26369 Out-of-bounds Read vulnerability in Intel XMM 7560 Firmware
Out-of-bounds read in some Intel(R) XMM(TM) 7560 Modem software before version M2_7560_R_01.2146.00 may allow a privileged user to potentially enable escalation of privilege via adjacent access.
low complexity
intel CWE-125
8.1
2022-11-11 CVE-2022-26508 Improper Authentication vulnerability in Intel Server Debug and Provisioning Tool
Improper authentication in the Intel(R) SDP Tool before version 3.0.0 may allow an unauthenticated user to potentially enable information disclosure via network access.
network
low complexity
intel CWE-287
7.5
2022-11-11 CVE-2022-27187 Uncontrolled Search Path Element vulnerability in Intel Quartus Prime
Uncontrolled search path element in the Intel(R) Quartus Prime Standard edition software before version 21.1 Patch 0.02std may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-427
7.8
2022-11-11 CVE-2022-27233 XML Injection (aka Blind XPath Injection) vulnerability in Intel Quartus Prime
XML injection in the Quartus(R) Prime Programmer included in the Intel(R) Quartus Prime Pro and Standard edition software may allow an unauthenticated user to potentially enable information disclosure via network access.
network
low complexity
intel CWE-91
7.5
2022-11-11 CVE-2022-27497 NULL Pointer Dereference vulnerability in Intel Active Management Technology Firmware
Null pointer dereference in firmware for Intel(R) AMT before version 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 may allow an unauthenticated user to potentially enable denial of service via network access.
network
low complexity
intel CWE-476
7.5
2022-11-11 CVE-2022-27638 Uncontrolled Search Path Element vulnerability in Intel Advanced Link Analyzer
Uncontrolled search path element in the Intel(R) Advanced Link Analyzer Pro before version 22.2 and Standard edition software before version 22.1.1 STD may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-427
7.8
2022-11-11 CVE-2022-27639 Incomplete Cleanup vulnerability in Intel XMM 7560 Firmware
Incomplete cleanup in some Intel(R) XMM(TM) 7560 Modem software before version M2_7560_R_01.2146.00 may allow a privileged user to potentially enable escalation of privilege via adjacent access.
low complexity
intel CWE-459
8.4