CVE-2020-0596: Input Validation
Improper input validation in DHCPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable information disclosure via network access.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2020-0596.
What is the severity of CVE-2020-0596?
The severity of CVE-2020-0596 is high with a score of 7.5.
Which software versions are affected by CVE-2020-0596?
Intel Active Management Technology Firmware versions before 11.8.77, 11.12.77, 11.22.77, and 12.0.64, as well as Intel Service Manager versions before 11.8.77, 11.12.77, 11.22.77, and 12.0.64 are affected by CVE-2020-0596.
How can an unauthenticated user potentially enable information disclosure via network access due to CVE-2020-0596?
An unauthenticated user can potentially enable information disclosure via network access by exploiting the improper input validation in the DHCPv6 subsystem of Intel AMT and Intel ISM.
Where can I find more information about CVE-2020-0596?
You can find more information about CVE-2020-0596 at the following references: [Reference 1](https://security.netapp.com/advisory/ntap-20200611-0007/), [Reference 2](https://support.lenovo.com/de/en/product_security/len-30041), [Reference 3](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00295.html).