MEDIUM
Out-of-bounds read in DHCPv6 subsystem in Intel(R) AMT and Intel(R)ISM versions before 11.8.77, 11.12.77, 11.22.77, 12.0.64 and 14.0.33 may allow an unauthenticated user to potentially enable information disclosure via network access
Published Jun 15, 2020
5.3
MEDIUMCVSS 3.1
EPSS 1.79%
Description
Out-of-bounds read in DHCPv6 subsystem in Intel(R) AMT and Intel(R)ISM versions before 11.8.77, 11.12.77, 11.22.77, 12.0.64 and 14.0.33 may allow an unauthenticated user to potentially enable information disclosure via network access.
Affected products
- Vendor n/a Product Intel(R) AMT and Intel(R) ISM Defaultunknown
Affected
- See provided reference
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | Intel(R) AMT and Intel(R) ISM | unknown | Affected
|
Configuration 1
OR
- ≥ 11.0 · < 11.8.77
- ≥ 11.10 · < 11.12.77
- ≥ 11.20 · < 11.22.77
- ≥ 12.0 · < 12.0.64
- ≥ 14.0 · < 14.0.33
Configuration 2
OR
- ≥ 11.0 · < 11.8.77
- ≥ 11.10 · < 11.12.77
- ≥ 11.20 · < 11.22.77
- ≥ 12.0 · < 12.0.64
- ≥ 14.0 · < 14.0.33
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-29522 Advisory
- https://security.netapp.com/advisory/ntap-20200611-0007/ x_refsource_CONFIRM
- https://support.lenovo.com/de/en/product_security/len-30041 x_refsource_MISC
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00295.html x_refsource_CONFIRMVendor Advisory
- https://www.kb.cert.org/vuls/id/257161 third-party-advisoryx_refsource_CERT-VN
- https://www.synology.com/security/advisory/Synology_SA_20_15 x_refsource_CONFIRMThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-29522 | Advisory | |
| https://security.netapp.com/advisory/ntap-20200611-0007/ | x_refsource_CONFIRM | |
| https://support.lenovo.com/de/en/product_security/len-30041 | x_refsource_MISC | |
| https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00295.html | x_refsource_CONFIRMVendor Advisory | |
| https://www.kb.cert.org/vuls/id/257161 | third-party-advisoryx_refsource_CERT-VN | |
| https://www.synology.com/security/advisory/Synology_SA_20_15 | x_refsource_CONFIRMThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner intel
Published Jun 15, 2020
Updated Aug 4, 2024
Reserved Feb 6, 2020
Link CVE-2020-8674
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data