CVE Vulnerabilities

CVE-2020-8758

Published: Sep 10, 2020 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Improper buffer restrictions in network subsystem in provisioned Intel(R) AMT and Intel(R) ISM versions before 11.8.79, 11.12.79, 11.22.79, 12.0.68 and 14.0.39 may allow an unauthenticated user to potentially enable escalation of privilege via network access. On un-provisioned systems, an authenticated user may potentially enable escalation of privilege via local access.

Affected Software

NameVendorStart VersionEnd Version
Standard_manageabilityIntel11.8 (including)11.8.79 (excluding)
Standard_manageabilityIntel11.12 (including)11.12.79 (excluding)
Standard_manageabilityIntel11.22 (including)11.22.79 (excluding)
Standard_manageabilityIntel12.0 (including)12.0.68 (excluding)
Standard_manageabilityIntel14.0 (including)14.0.39 (excluding)
Active_management_technology_firmwareIntel11.8 (including)11.8.79 (excluding)
Active_management_technology_firmwareIntel11.12 (including)11.12.79 (excluding)
Active_management_technology_firmwareIntel11.22 (including)11.22.79 (excluding)
Active_management_technology_firmwareIntel12.0 (including)12.0.68 (excluding)
Active_management_technology_firmwareIntel14.0 (including)14.0.39 (excluding)

References