Impact
This vulnerability stems from improper input validation in certain firmware modules of Intel Active Management Technology (Intel AMT) and Intel Standard Manageability. An attacker who can send malformed data to the AMT interface will trigger a denial of service condition, causing the AMT subsystem to become unreachable or reset. The weakness is classified as CWE‑20, which indicates invalid handling of external input that can lead to failure states such as service crash or denial of service. The flaw does not compromise confidentiality or integrity; its sole impact is on system availability.
Affected Systems
Devices that implement Intel AMT or Intel Standard Manageability firmware are affected, though the CVE entry does not enumerate specific device models or firmware revisions. Users should consult Intel’s advisory (INTEL‑SA‑01427) or the vendor’s support portal to identify whether their hardware and firmware versions are listed as impacted.
Risk and Exploitability
The CVSS score of 8.2 marks this issue as high severity. Although the EPSS score is <1%, indicating a low likelihood of current exploitation, organizations exposing AMT interfaces to untrusted networks face a real risk because the attack requires no authentication, can be launched remotely over the network, and needs no user interaction. The vulnerability is not present in the CISA KEV catalog, but the lack of publicly documented exploitation does not diminish the need for timely remediation.
OpenCVE Enrichment