CVE-2020-0596
Improper input validation in DHCPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable information disclosure via network access.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.21%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Improper input validation in DHCPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable information disclosure via network access.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 2.21% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- intel/active management technology firmware · intel/service manager
- Source
- secure@intel.com
References
- https://security.netapp.com/advisory/ntap-20200611-0007/
- https://support.lenovo.com/de/en/product_security/len-30041
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00295.htmlVendor Advisory
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00295.htmlVendor Advisory
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00295.htmlVendor Advisory
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00295.htmlVendor Advisory
- https://www.synology.com/security/advisory/Synology_SA_20_15Third Party Advisory
- https://security.netapp.com/advisory/ntap-20200611-0007/
- https://support.lenovo.com/de/en/product_security/len-30041
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00295.htmlVendor Advisory
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00295.htmlVendor Advisory
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00295.htmlVendor Advisory
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00295.htmlVendor Advisory
- https://www.synology.com/security/advisory/Synology_SA_20_15Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.