CRITICAL
Use after free in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable escalation of privilege via network access
Published Jun 15, 2020
9.8
CRITICALCVSS 3.1
EPSS 3.44%
Description
Use after free in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable escalation of privilege via network access.
Affected products
- Vendor n/a Product Intel(R) AMT and Intel(R) ISM Defaultn/a
- Version See provided referenceStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Intel(R) AMT and Intel(R) ISM | n/a |
|
Configuration 1
OR
- ≥ 11.0 · < 11.8.77
- ≥ 11.10 · < 11.12.77
- ≥ 11.20 · < 11.22.77
- ≥ 12.0 · < 12.0.64
Configuration 2
OR
- ≥ 11.0 · < 11.8.77
- ≥ 11.10 · < 11.12.77
- ≥ 11.20 · < 11.22.77
- ≥ 12.0 · < 12.0.64
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-2093 Advisory
- https://security.netapp.com/advisory/ntap-20200611-0007/ x_refsource_CONFIRM
- https://support.lenovo.com/de/en/product_security/len-30041 x_refsource_MISC
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00295.html x_refsource_CONFIRMVendor Advisory
- https://www.kb.cert.org/vuls/id/257161 third-party-advisoryx_refsource_CERT-VN
- https://www.synology.com/security/advisory/Synology_SA_20_15 x_refsource_CONFIRMThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-2093 | Advisory | |
| https://security.netapp.com/advisory/ntap-20200611-0007/ | x_refsource_CONFIRM | |
| https://support.lenovo.com/de/en/product_security/len-30041 | x_refsource_MISC | |
| https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00295.html | x_refsource_CONFIRMVendor Advisory | |
| https://www.kb.cert.org/vuls/id/257161 | third-party-advisoryx_refsource_CERT-VN | |
| https://www.synology.com/security/advisory/Synology_SA_20_15 | x_refsource_CONFIRMThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner intel
Published Jun 15, 2020
Updated Aug 4, 2024
Reserved Oct 28, 2019
Link CVE-2020-0595
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2020-2093 Assigner intel
Published Jun 15, 2020
Updated Aug 4, 2024
Exploited since n/a
Link EUVD-2020-2093