PT-2022-5918 · Intel · Killer Wifi+2
Julien Lenoir
·
Published
2022-11-11
·
Updated
2023-09-27
·
CVE-2022-26047
CVSS v3.1
6.5
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Intel(R) PROSet/Wireless WiFi versions (affected versions not specified)
Intel vPro(R) CSME WiFi versions (affected versions not specified)
Killer(TM) WiFi versions (affected versions not specified)
Description
The issue is related to improper input validation in some Intel WiFi products, which may allow an unauthenticated user to potentially enable denial of service via local access. This could be exploited by a remote attacker to cause a denial of service.
Recommendations
For Intel(R) PROSet/Wireless WiFi, consider disabling the vulnerable input validation function until a patch is available.
For Intel vPro(R) CSME WiFi, restrict access to the WiFi module to minimize the risk of exploitation.
For Killer(TM) WiFi, avoid using the product until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Intel Proset/Wireless Wifi
Intel Vpro Csme Wifi
Killer Wifi