CVE-2020-8674Out-of-bounds Read in Intel Active Management Technology Firmware

CWE-125Out-of-bounds Read4 documents4 sources
Severity
5.3MEDIUMNVD
EPSS
1.2%
top 20.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 15
Latest updateMay 24

Description

Out-of-bounds read in DHCPv6 subsystem in Intel(R) AMT and Intel(R)ISM versions before 11.8.77, 11.12.77, 11.22.77, 12.0.64 and 14.0.33 may allow an unauthenticated user to potentially enable information disclosure via network access.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

NVDintel/service_manager11.011.8.77+4

🔴Vulnerability Details

2
GHSA
GHSA-cc9v-qmm3-2w98: Out-of-bounds read in DHCPv6 subsystem in Intel(R) AMT and Intel(R)ISM versions before 112022-05-24
CVEList
CVE-2020-8674: Out-of-bounds read in DHCPv6 subsystem in Intel(R) AMT and Intel(R)ISM versions before 112020-06-15

💬Community

1
Bugzilla
CVE-2019-8674 webkitgtk: Incorrect state management leading to universal cross-site scripting2020-09-07
CVE-2020-8674 — Out-of-bounds Read in Intel | cvebase