CVE-2020-0537
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
15/06/2020
Last modified:
22/07/2020
Description
Improper input validation in subsystem for Intel(R) AMT versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow a privileged user to potentially enable denial of service via network access.
Impact
Base Score 3.x
4.90
Severity 3.x
MEDIUM
Base Score 2.0
4.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:intel:active_management_technology_firmware:*:*:*:*:*:*:*:* | 11.0 (including) | 11.8.77 (excluding) |
| cpe:2.3:o:intel:active_management_technology_firmware:*:*:*:*:*:*:*:* | 11.10 (including) | 11.12.77 (excluding) |
| cpe:2.3:o:intel:active_management_technology_firmware:*:*:*:*:*:*:*:* | 11.20 (including) | 11.22.77 (excluding) |
| cpe:2.3:o:intel:active_management_technology_firmware:*:*:*:*:*:*:*:* | 12.0 (including) | 12.0.64 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



