CVE-2020-12356: Medium severity intel active management technology vulnerability
Published Nov 12, 2020
·Updated
Out-of-bounds read in subsystem in Intel(R) AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow a privileged user to potentially enable information disclosure via local access.
Affected Software
6 affected components
Intel Active Management Technology Firmware<11.8.80
Intel Active Management Technology Firmware>=11.12.0<11.12.80
Intel Active Management Technology Firmware>=11.22.0<11.22.80
Intel Active Management Technology Firmware>=12.0<12.0.70
Intel Active Management Technology Firmware>=14.0<14.0.45
NetApp Cloud Backup
Event History
Nov 12, 2020
CVE Published
via MITRE·06:09 PM
Data Sourced
via MITRE·06:09 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2020-12356?
CVE-2020-12356 is an out-of-bounds read vulnerability in the subsystem of Intel(R) AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, and 14.0.45.
2
What is the severity of CVE-2020-12356?
The severity of CVE-2020-12356 is medium with a CVSS score of 4.4.
3
How can a privileged user exploit CVE-2020-12356?
A privileged user can potentially enable information disclosure through local access.
4
Which software versions are affected by CVE-2020-12356?
Intel AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, and 14.0.45 are affected by CVE-2020-12356.
5
Where can I find more information about CVE-2020-12356?
You can find more information about CVE-2020-12356 on the Netapp and Intel security advisories.