← Vulnerability feed

Vulnerability record · CVE-2020-12315 · published 12 November 2020

CVE-2020-12315: Intel endpoint management assistant path traversal vulnerability

Intel · Endpoint Management Assistant

Path traversal in the Intel(R) EMA before version 1.3.3 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

9.8 CVSS 3.1 Critical EPSS 1.7% · top 23.1% CWE-22 · Path traversal
9.8CVSS 3.1 base score, v2 7.5
1.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Path traversal in the Intel(R) EMA before version 1.3.3 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-12315 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2022-26341Intel active management technology software development kit insufficiently protected credentials vulnerabilityInsufficiently protected credentials in software in Intel(R) AMT SDK before version 16.0.4.1, Intel(R) EMA before version 1.7.1 and Intel(R) MC befor…EPSS 0.47%8.7CVE-2025-35990Intel endpoint management assistant improper input validation vulnerabilityImproper input validation for some Intel Endpoint Management Assistant (EMA) software before version 1.14.5 within Ring 3: User Applications may allo…EPSS 0.22%7.8CVE-2022-30297Intel endpoint management assistant cross-site scripting vulnerabilityCross-site scripting in the Intel(R) EMA software before version 1.8.0 may allow a privileged user to potentially enable escalation of privilege via …EPSS 0.17%7.5CVE-2021-0013Intel endpoint management assistant improper input validation vulnerabilityImproper input validation for Intel(R) EMA before version 1.5.0 may allow an unauthenticated user to potentially enable denial of service via network…EPSS 0.98%7.0CVE-2024-32483Intel endpoint management assistant improper access control vulnerabilityImproper access control for some Intel(R) EMA software before version 1.13.1.0 may allow an authenticated user to potentially enable escalation of pr…EPSS 0.17%5.5CVE-2022-45128Intel endpoint management assistant improper authorization vulnerabilityImproper authorization in the Intel(R) EMA software before version 1.9.0.0 may allow an authenticated user to potentially enable denial of service vi…EPSS 0.16%5.5CVE-2020-12316Intel endpoint management assistant insufficiently protected credentials vulnerabilityInsufficiently protected credentials in the Intel(R) EMA before version 1.3.3 may allow an authorized user to potentially enable information disclosu…EPSS 0.28%5.3CVE-2022-38056Intel endpoint management assistant vulnerabilityImproper neutralization in the Intel(R) EMA software before version 1.8.1.0 may allow a privileged user to potentially enable escalation of privilege…EPSS 0.15%

Source: NIST National Vulnerability Database (record CVE-2020-12315), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.