CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2020-8758

CVSS 9.8v3.1pub. 2020-09-10upd. 2024-11-21

Improper buffer restrictions in network subsystem in provisioned Intel(R) AMT and Intel(R) ISM versions before 11.8.79, 11.12.79, 11.22.79, 12.0.68 and 14.0.39 may allow an unauthenticated user to potentially enable escalation of privilege via network access. On un-provisioned systems, an authenticated user may potentially enable escalation of privilege via local access.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Intel Active Management Technology Firmware

    OS
    Intel
    11.8 – 11.8.79 (excl.)11.12 – 11.12.79 (excl.)11.22 – 11.22.79 (excl.)12.0 – 12.0.68 (excl.)14.0 – 14.0.39 (excl.)
  • Intel Standard Manageability

    APP
    Intel
    11.8 – 11.8.79 (excl.)11.12 – 11.12.79 (excl.)11.22 – 11.22.79 (excl.)12.0 – 12.0.68 (excl.)14.0 – 14.0.39 (excl.)
  • Netapp Steelstore Cloud Integrated Storage

    APP
    Netapp
    all versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2017-5689CRITICAL9.8⚠ KEVPL ✓same product

Privilege Escalation w Intel AMT/ISM/SBT — nieautoryzowany dostęp systemowy

CVE-2022-30601CRITICAL9.8PL ✓same product

Niewystarczająco chronione dane uwierzytelniające w Intel AMT i Intel Standard Manageability

CVE-2020-8752CRITICAL9.8PL ✓same product

Out-of-bounds write w IPv6 Intel AMT/ISM umożliwia privilege escalation

CVE-2020-8747CRITICAL9.1PL ✓same product

Out-of-bounds read w Intel AMT — ujawnienie danych i DoS przez sieć

CVE-2020-0594CRITICAL9.8PL ✓same product

Out-of-bounds read w IPv6 w Intel AMT i ISM umożliwia privilege escalation