CVE-2020-0596 describes an improper input validation vulnerability within the DHCPv6 subsystem of Intel Active Management Technology (AMT) and Intel Service Manager (ISM) firmware versions prior to 11.8.77, 11.12.77, 11.22.77, and 12.0.64. This flaw allows an unauthenticated attacker to potentially disclose sensitive information over the network. With a CVSS score of 7.5 (High), the vulnerability is easily exploitable via the network with low attack complexity, though it only impacts confidentiality. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in CISA's KEV catalog. Despite this, the vulnerability has garnered some community discussion and media coverage, including a mention in a BleepingComputer article about Intel's June 2020 platform updates.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 11.0, < 11.8.77CPE matchmatch criteria | cpe:2.3:o:intel:active_management_technology_firmware:*:*:*:*:*:*:*:* | ||
>= 11.10, < 11.12.77CPE matchmatch criteria | cpe:2.3:o:intel:active_management_technology_firmware:*:*:*:*:*:*:*:* | ||
>= 11.20, < 11.22.77CPE matchmatch criteria | cpe:2.3:o:intel:active_management_technology_firmware:*:*:*:*:*:*:*:* | ||
>= 12.0, < 12.0.64CPE matchmatch criteria | cpe:2.3:o:intel:active_management_technology_firmware:*:*:*:*:*:*:*:* | ||
>= 11.0, < 11.8.77CPE matchmatch criteria | cpe:2.3:a:intel:service_manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.