PT-2024-11602 · Intel · Intel Ethernet Controller I225 Manageability+1

Published

2024-05-16

·

Updated

2024-05-17

·

CVE-2022-37341

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware (affected versions not specified)
Description The issue is related to improper access control in the firmware of certain Intel Ethernet Adapters and Intel Ethernet Controller I225 Manageability. This may allow a privileged user to potentially enable escalation of privilege via local access.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2022-37341

Affected Products

Intel Ethernet Adapters
Intel Ethernet Controller I225 Manageability