CVE-2020-0536: Input Validation
Improper input validation in the DAL subsystem for Intel(R) CSME versions before 11.8.77, 11.12.77, 11.22.77, 12.0.64, 13.0.32,14.0.33 and Intel(R) TXE versions before 3.1.75 and 4.0.25 may allow an unauthenticated user to potentially enable information disclosure via network access.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-0536?
CVE-2020-0536 is a vulnerability in the DAL subsystem for Intel(R) CSME and Intel(R) TXE that may allow an unauthenticated user to enable information disclosure via network access.
What is the severity of CVE-2020-0536?
The severity of CVE-2020-0536 is high, with a score of 7.5.
Which software versions are affected by CVE-2020-0536?
CVE-2020-0536 affects Intel(R) CSME versions before 11.8.77, 11.12.77, 11.22.77, 12.0.64, 13.0.32, and 14.0.33, as well as Intel(R) TXE versions before 3.1.75 and 4.0.25.
How can an unauthenticated user potentially exploit CVE-2020-0536?
An unauthenticated user can potentially exploit CVE-2020-0536 by enabling information disclosure via network access.
Where can I find more information about CVE-2020-0536?
You can find more information about CVE-2020-0536 in the references provided: https://security.netapp.com/advisory/ntap-20200611-0006/, https://support.lenovo.com/de/en/product_security/len-30041, and https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00295.html.