E17-0fnt1
CVSS:
9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
False Positive:
f
Variants:
1
Year:
2017
Description
This strike exploits a privilege escalation vulnerability in Intel Active Management Technology.
The vulnerability is due to improper input validation when checking parameters in the Authorization HTTP request header.
An unprivileged attacker can gain system privileges of AMT by sending an HTTP Digest authentication request with an empty response parameter.
CVE
References
https://www.embedi.com/files/white-papers/Silent-Bob-is-Silent.pdf