CVE-2020-0535 describes an improper input validation vulnerability in Intel Active Management Technology (AMT) firmware versions before 11.8.76, 11.12.77, 11.22.77, and 12.0.64. This flaw could allow an unauthenticated attacker to gain information via network access. The vulnerability has a CVSS score of 5.3 (Medium), indicating a low attack complexity and no user interaction required, but only leads to potential information disclosure (Confidentiality impact Low). Its EPSS score is low, suggesting a minimal likelihood of exploitation. While there is no known public exploit code (Metasploit, Nuclei, ExploitDB) and it is not listed in the KEV catalog, the CVE has garnered some community discussion and media coverage, including a mention in a BleepingComputer article regarding Intel's June 2020 platform updates.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 11.0, < 11.8.77CPE matchmatch criteria | cpe:2.3:o:intel:active_management_technology_firmware:*:*:*:*:*:*:*:* | ||
>= 11.10, < 11.12.77CPE matchmatch criteria | cpe:2.3:o:intel:active_management_technology_firmware:*:*:*:*:*:*:*:* | ||
>= 11.20, < 11.22.77CPE matchmatch criteria | cpe:2.3:o:intel:active_management_technology_firmware:*:*:*:*:*:*:*:* | ||
>= 12.0, < 12.0.64CPE matchmatch criteria | cpe:2.3:o:intel:active_management_technology_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.