PT-2022-5918 · Intel · Killer Wifi+2

Julien Lenoir

·

Published

2022-11-11

·

Updated

2023-09-27

·

CVE-2022-26047

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Intel(R) PROSet/Wireless WiFi versions (affected versions not specified) Intel vPro(R) CSME WiFi versions (affected versions not specified) Killer(TM) WiFi versions (affected versions not specified)
Description The issue is related to improper input validation in some Intel WiFi products, which may allow an unauthenticated user to potentially enable denial of service via local access. This could be exploited by a remote attacker to cause a denial of service.
Recommendations For Intel(R) PROSet/Wireless WiFi, consider disabling the vulnerable input validation function until a patch is available. For Intel vPro(R) CSME WiFi, restrict access to the WiFi module to minimize the risk of exploitation. For Killer(TM) WiFi, avoid using the product until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

BDU:2022-07338
CVE-2022-26047

Affected Products

Intel Proset/Wireless Wifi
Intel Vpro Csme Wifi
Killer Wifi