← Vulnerability feed

Vulnerability record · CVE-2022-26341 · published 11 November 2022

CVE-2022-26341: Intel active management technology software development kit insufficiently protected credentials vulnerability

Intel · Active Management Technology Software Development Kit

Insufficiently protected credentials in software in Intel(R) AMT SDK before version 16.0.4.1, Intel(R) EMA before version 1.7.1 and Intel(R) MC before version 2.3.2 may allow an authenticated user to potentially enable escalation of privilege via network access.

8.8 CVSS 3.1 High EPSS 0.47% · top 62.2% CWE-522 · Insufficiently protected credentials
8.8CVSS 3.1 base score
0.47%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Insufficiently protected credentials in software in Intel(R) AMT SDK before version 16.0.4.1, Intel(R) EMA before version 1.7.1 and Intel(R) MC before version 2.3.2 may allow an authenticated user to potentially enable escalation of privilege via network access.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-26341 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-12315Intel endpoint management assistant path traversal vulnerabilityPath traversal in the Intel(R) EMA before version 1.3.3 may allow an unauthenticated user to potentially enable escalation of privilege via network a…EPSS 1.7%9.6CVE-2022-29887Intel manageability commander cross-site scripting vulnerabilityCross-site Scripting (XSS) in some Intel(R) Manageability Commander software before version 2.3 may allow an unauthenticated user to potentially enab…EPSS 0.66%8.7CVE-2025-35990Intel endpoint management assistant improper input validation vulnerabilityImproper input validation for some Intel Endpoint Management Assistant (EMA) software before version 1.14.5 within Ring 3: User Applications may allo…EPSS 0.22%8.0CVE-2021-0126Intel manageability commander improper input validation vulnerabilityImproper input validation for the Intel(R) Manageability Commander before version 2.2 may allow an authenticated user to potentially enable escalatio…EPSS 0.39%7.8CVE-2022-30297Intel endpoint management assistant cross-site scripting vulnerabilityCross-site scripting in the Intel(R) EMA software before version 1.8.0 may allow a privileged user to potentially enable escalation of privilege via …EPSS 0.17%7.8CVE-2020-12354Intel active management technology software development kit incorrect default permissions vulnerabilityIncorrect default permissions in Windows(R) installer in Intel(R) AMT SDK versions before 14.0.0.1 may allow an authenticated user to potentially ena…EPSS 0.34%7.5CVE-2021-0013Intel endpoint management assistant improper input validation vulnerabilityImproper input validation for Intel(R) EMA before version 1.5.0 may allow an unauthenticated user to potentially enable denial of service via network…EPSS 0.98%7.0CVE-2024-32483Intel endpoint management assistant improper access control vulnerabilityImproper access control for some Intel(R) EMA software before version 1.13.1.0 may allow an authenticated user to potentially enable escalation of pr…EPSS 0.17%

Source: NIST National Vulnerability Database (record CVE-2022-26341), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.