Intel records
1,868 published records for vendor intel.
Researcher profile
- Entered KEV
- 4 · 0.2%
- Weaponized
- 5 · 0.3%
- Pre-auth RCE
- 15
- With a fix record
- 9.6%
- Median publish → KEV
- 1118 days
Recurring classes
- CWE-20 Improper Input Validation272
- CWE-427 Uncontrolled Search Path Element162
- CWE-284 Improper Access Control106
- CWE-276 Incorrect Default Permissions87
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer71
- CWE-787 Out-of-bounds Write68
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
1,868 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
100Now | CVE-2021-44228Weaponized | Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpointsapache · log4j · CWE-20 | Critical10.0 | KEV | 100.0% | Dec 10, 2021 |
97Now | CVE-2017-5689Weaponized | An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (Aintel · active management technology firmware · CWE-269 | Critical9.8 | KEV | 92.2% | May 2, 2017 |
96Now | CVE-2021-45046Weaponized | Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attackapache · log4j · CWE-917 | Critical9.0 | KEV | 100.0% | Dec 14, 2021 |
64This week | CVE-2015-2291Weaponized | (1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cintel · ethernet diagnostics driver iqvw32.sys · CWE-20 | High7.8 | KEV | 9.0% | Aug 9, 2017 |
54Plan | CVE-2013-4786Weaponized | The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote attackers to obtainoracle · fujitsu m10 firmware · CWE-255 | High7.5 | — | 78.6% | Jul 8, 2013 |
51Plan | CVE-2024-22476Proof of concept | Improper input validation in some Intel(R) Neural Compressor software before version 2.5.0 may allow an unauthenticated user to potentially CWE-20 | Critical10.0 | — | 36.0% | May 16, 2024 |
50Plan | CVE-2017-5753Proof of concept | Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an atintel · atom c · CWE-203 | Medium5.6 | — | 93.8% | Jan 4, 2018 |
47Plan | CVE-2017-5754Proof of concept | Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of informationintel · atom c · CWE-200 | Medium5.6 | — | 84.2% | Jan 4, 2018 |
44Plan | CVE-2017-5715Proof of concept | Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of informationintel · atom c · CWE-203 | Medium5.6 | — | 74.0% | Jan 4, 2018 |
42Plan | CVE-2000-0384Proof of concept | NetStructure 7110 and 7180 have undocumented accounts (servnow, root, and wizard) whose passwords are easily guessable from the NetStructureintel · netstructure 7110 | Critical10.0 | — | 5.9% | May 8, 2000 |
41Plan | CVE-2009-1385No exploit | Integer underflow in the e1000_clean_rx_irq function in drivers/net/e1000/e1000_main.c in the e1000 driver in the Linux kernel before 2.6.30linux · kernel · CWE-189 | High7.8 | — | 33.7% | Jun 4, 2009 |
41Plan | CVE-2017-12865Proof of concept | Stack-based buffer overflow in "dnsproxy.c" in connman 1.34 and earlier allows remote attackers to cause a denial of service (crash) or execintel · connman · CWE-119 | Critical9.8 | — | 5.5% | Aug 29, 2017 |
40Plan | CVE-2018-3639Proof of concept | Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memintel · atom c · CWE-203 | Medium5.5 | — | 60.6% | May 22, 2018 |
40Plan | CVE-2020-0594No exploit | Out-of-bounds read in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an uintel · active management technology firmware · CWE-125 | Critical9.8 | — | 3.5% | Jun 15, 2020 |
40Plan | CVE-2020-0595No exploit | Use after free in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unautintel · active management technology firmware · CWE-416 | Critical9.8 | — | 3.4% | Jun 15, 2020 |
40Plan | CVE-2022-32292No exploit | In ConnMan through 1.41, remote attackers able to send HTTP requests to the gweb component are able to exploit a heap-based buffer overflow intel · connman · CWE-787 | Critical9.8 | — | 3.2% | Aug 3, 2022 |
40Plan | CVE-2020-11486No exploit | NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmware in which softwarenvidia · dgx-1 · CWE-434 | Critical9.8 | — | 2.7% | Oct 29, 2020 |
40Plan | CVE-2021-33833No exploit | ConnMan (aka Connection Manager) 1.30 through 1.39 has a stack-based buffer overflow in uncompress in dnsproxy.c via NAME, RDATA, or RDLENGTintel · connection manager · CWE-787 | Critical9.8 | — | 2.6% | Jun 9, 2021 |
40Plan | CVE-2019-0172No exploit | A logic issue in Intel Unite(R) Client for Android prior to version 4.0 may allow a remote attacker to potentially enable escalation of privintel · unite | Critical9.8 | — | 2.3% | May 17, 2019 |
40Plan | CVE-2018-12171No exploit | Privilege escalation in Intel Baseboard Management Controller (BMC) firmware before version 1.43.91f76955 may allow an unprivileged user to intel · bmc firmware | Critical9.8 | — | 2.1% | Sep 12, 2018 |
40Plan | CVE-2019-11119No exploit | Insufficient session validation in the service API for Intel(R) RWC3 version 4.186 and before may allow an unauthenticated user to potentialintel · raid web console 3 | Critical9.8 | — | 2.0% | Jun 13, 2019 |
40Plan | CVE-2020-8758No exploit | Improper buffer restrictions in network subsystem in provisioned Intel(R) AMT and Intel(R) ISM versions before 11.8.79, 11.12.79, 11.22.79, intel · standard manageability | Critical9.8 | — | 1.9% | Sep 10, 2020 |
40Plan | CVE-2019-0153No exploit | Buffer overflow in subsystem in Intel(R) CSME 12.0.0 through 12.0.34 may allow an unauthenticated user to potentially enable escalation of pintel · converged security management engine firmware · CWE-119 | Critical9.8 | — | 1.9% | May 17, 2019 |
40Plan | CVE-2019-0101No exploit | Authentication bypass in the Intel Unite(R) solution versions 3.2 through 3.3 may allow an unauthenticated user to potentially enable escalaintel · unite | Critical9.8 | — | 1.8% | Feb 18, 2019 |
40Plan | CVE-2019-11131No exploit | Logic issue in subsystem in Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentintel · active management technology firmware | Critical9.8 | — | 1.8% | Dec 18, 2019 |
- CVE-2021-44228100Now
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
CriticalCVSS 10.0KEVWeaponizedEPSS 100%apache · log4jDec 10, 2021
- CVE-2017-568997Now
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (A
CriticalCVSS 9.8KEVWeaponizedEPSS 92%intel · active management technology firmwareMay 2, 2017
- CVE-2021-4504696Now
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
CriticalCVSS 9.0KEVWeaponizedEPSS 100%apache · log4jDec 14, 2021
- CVE-2015-229164This week
(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to c
HighCVSS 7.8KEVWeaponizedEPSS 9%intel · ethernet diagnostics driver iqvw32.sysAug 9, 2017
- CVE-2013-478654Plan
The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote attackers to obtain
HighCVSS 7.5WeaponizedEPSS 79%oracle · fujitsu m10 firmwareJul 8, 2013
- CVE-2024-2247651Plan
Improper input validation in some Intel(R) Neural Compressor software before version 2.5.0 may allow an unauthenticated user to potentially
CriticalCVSS 10.0Proof of conceptEPSS 36%May 16, 2024
- CVE-2017-575350Plan
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an at
MediumCVSS 5.6Proof of conceptEPSS 94%intel · atom cJan 4, 2018
- CVE-2017-575447Plan
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information
MediumCVSS 5.6Proof of conceptEPSS 84%intel · atom cJan 4, 2018
- CVE-2017-571544Plan
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information
MediumCVSS 5.6Proof of conceptEPSS 74%intel · atom cJan 4, 2018
- CVE-2000-038442Plan
NetStructure 7110 and 7180 have undocumented accounts (servnow, root, and wizard) whose passwords are easily guessable from the NetStructure
CriticalCVSS 10.0Proof of conceptEPSS 6%intel · netstructure 7110May 8, 2000
- CVE-2009-138541Plan
Integer underflow in the e1000_clean_rx_irq function in drivers/net/e1000/e1000_main.c in the e1000 driver in the Linux kernel before 2.6.30
HighCVSS 7.8No exploitEPSS 34%linux · kernelJun 4, 2009
- CVE-2017-1286541Plan
Stack-based buffer overflow in "dnsproxy.c" in connman 1.34 and earlier allows remote attackers to cause a denial of service (crash) or exec
CriticalCVSS 9.8Proof of conceptEPSS 6%intel · connmanAug 29, 2017
- CVE-2018-363940Plan
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior mem
MediumCVSS 5.5Proof of conceptEPSS 61%intel · atom cMay 22, 2018
- CVE-2020-059440Plan
Out-of-bounds read in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an u
CriticalCVSS 9.8No exploitEPSS 4%intel · active management technology firmwareJun 15, 2020
- CVE-2020-059540Plan
Use after free in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unaut
CriticalCVSS 9.8No exploitEPSS 3%intel · active management technology firmwareJun 15, 2020
- CVE-2022-3229240Plan
In ConnMan through 1.41, remote attackers able to send HTTP requests to the gweb component are able to exploit a heap-based buffer overflow
CriticalCVSS 9.8No exploitEPSS 3%intel · connmanAug 3, 2022
- CVE-2020-1148640Plan
NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmware in which software
CriticalCVSS 9.8No exploitEPSS 3%nvidia · dgx-1Oct 29, 2020
- CVE-2021-3383340Plan
ConnMan (aka Connection Manager) 1.30 through 1.39 has a stack-based buffer overflow in uncompress in dnsproxy.c via NAME, RDATA, or RDLENGT
CriticalCVSS 9.8No exploitEPSS 3%intel · connection managerJun 9, 2021
- CVE-2019-017240Plan
A logic issue in Intel Unite(R) Client for Android prior to version 4.0 may allow a remote attacker to potentially enable escalation of priv
CriticalCVSS 9.8No exploitEPSS 2%intel · uniteMay 17, 2019
- CVE-2018-1217140Plan
Privilege escalation in Intel Baseboard Management Controller (BMC) firmware before version 1.43.91f76955 may allow an unprivileged user to
CriticalCVSS 9.8No exploitEPSS 2%intel · bmc firmwareSep 12, 2018
- CVE-2019-1111940Plan
Insufficient session validation in the service API for Intel(R) RWC3 version 4.186 and before may allow an unauthenticated user to potential
CriticalCVSS 9.8No exploitEPSS 2%intel · raid web console 3Jun 13, 2019
- CVE-2020-875840Plan
Improper buffer restrictions in network subsystem in provisioned Intel(R) AMT and Intel(R) ISM versions before 11.8.79, 11.12.79, 11.22.79,
CriticalCVSS 9.8No exploitEPSS 2%intel · standard manageabilitySep 10, 2020
- CVE-2019-015340Plan
Buffer overflow in subsystem in Intel(R) CSME 12.0.0 through 12.0.34 may allow an unauthenticated user to potentially enable escalation of p
CriticalCVSS 9.8No exploitEPSS 2%intel · converged security management engine firmwareMay 17, 2019
- CVE-2019-010140Plan
Authentication bypass in the Intel Unite(R) solution versions 3.2 through 3.3 may allow an unauthenticated user to potentially enable escala
CriticalCVSS 9.8No exploitEPSS 2%intel · uniteFeb 18, 2019
- CVE-2019-1113140Plan
Logic issue in subsystem in Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potent
CriticalCVSS 9.8No exploitEPSS 2%intel · active management technology firmwareDec 18, 2019