← Vulnerability feed

Vulnerability record · CVE-2022-38056 · published 16 February 2023

CVE-2022-38056: Intel endpoint management assistant vulnerability

Intel · Endpoint Management Assistant

Improper neutralization in the Intel(R) EMA software before version 1.8.1.0 may allow a privileged user to potentially enable escalation of privilege via network access.

5.3 CVSS 3.1 Medium EPSS 0.15% · top 96.7%
5.3CVSS 3.1 base score
0.15%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Improper neutralization in the Intel(R) EMA software before version 1.8.1.0 may allow a privileged user to potentially enable escalation of privilege via network access.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-38056 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-12315Intel endpoint management assistant path traversal vulnerabilityPath traversal in the Intel(R) EMA before version 1.3.3 may allow an unauthenticated user to potentially enable escalation of privilege via network a…EPSS 1.7%8.8CVE-2022-26341Intel active management technology software development kit insufficiently protected credentials vulnerabilityInsufficiently protected credentials in software in Intel(R) AMT SDK before version 16.0.4.1, Intel(R) EMA before version 1.7.1 and Intel(R) MC befor…EPSS 0.47%8.7CVE-2025-35990Intel endpoint management assistant improper input validation vulnerabilityImproper input validation for some Intel Endpoint Management Assistant (EMA) software before version 1.14.5 within Ring 3: User Applications may allo…EPSS 0.22%7.8CVE-2022-30297Intel endpoint management assistant cross-site scripting vulnerabilityCross-site scripting in the Intel(R) EMA software before version 1.8.0 may allow a privileged user to potentially enable escalation of privilege via …EPSS 0.17%7.5CVE-2021-0013Intel endpoint management assistant improper input validation vulnerabilityImproper input validation for Intel(R) EMA before version 1.5.0 may allow an unauthenticated user to potentially enable denial of service via network…EPSS 0.98%7.0CVE-2024-32483Intel endpoint management assistant improper access control vulnerabilityImproper access control for some Intel(R) EMA software before version 1.13.1.0 may allow an authenticated user to potentially enable escalation of pr…EPSS 0.17%5.5CVE-2022-45128Intel endpoint management assistant improper authorization vulnerabilityImproper authorization in the Intel(R) EMA software before version 1.9.0.0 may allow an authenticated user to potentially enable denial of service vi…EPSS 0.16%5.5CVE-2020-12316Intel endpoint management assistant insufficiently protected credentials vulnerabilityInsufficiently protected credentials in the Intel(R) EMA before version 1.3.3 may allow an authorized user to potentially enable information disclosu…EPSS 0.28%

Source: NIST National Vulnerability Database (record CVE-2022-38056), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.