CVE-2020-8674 is an out-of-bounds read vulnerability in the DHCPv6 subsystem of Intel AMT and Intel ISM firmware versions prior to 11.8.77, 11.12.77, 11.22.77, 12.0.64, and 14.0.33. This medium-severity vulnerability (CVSS 5.3) allows an unauthenticated attacker to potentially disclose information over the network with low attack complexity. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in CISA's KEV catalog. Community discussion and media coverage are minimal, with only one article noting its patch in a broader Intel update.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 11.0, < 11.8.77CPE matchmatch criteria | cpe:2.3:o:intel:active_management_technology_firmware:*:*:*:*:*:*:*:* | ||
>= 11.10, < 11.12.77CPE matchmatch criteria | cpe:2.3:o:intel:active_management_technology_firmware:*:*:*:*:*:*:*:* | ||
>= 11.20, < 11.22.77CPE matchmatch criteria | cpe:2.3:o:intel:active_management_technology_firmware:*:*:*:*:*:*:*:* | ||
>= 12.0, < 12.0.64CPE matchmatch criteria | cpe:2.3:o:intel:active_management_technology_firmware:*:*:*:*:*:*:*:* | ||
>= 14.0, < 14.0.33CPE matchmatch criteria | cpe:2.3:o:intel:active_management_technology_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.