CVE-2020-0536
Estado: ModificadaAlta (7.5)—
Improper input validation in the DAL subsystem for Intel(R) CSME versions before 11.8.77, 11.12.77, 11.22.77, 12.0.64, 13.0.32,14.0.33 and Intel(R) TXE versions before 3.1.75 and 4.0.25 may allow an unauthenticated user to potentially enable information disclosure via network access.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.70%
- Percentil entre todas las CVEs puntuadas: 76
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-20
Referencias
- https://security.netapp.com/advisory/ntap-20200611-0006/
- https://support.lenovo.com/de/en/product_security/len-30041
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00295.html
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00295.html
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00295.html
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00295.html
- https://security.netapp.com/advisory/ntap-20200611-0006/
- https://support.lenovo.com/de/en/product_security/len-30041
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00295.html
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00295.html
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00295.html
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00295.html
JSON original (NVD)
Mostrar
{
"id": "CVE-2020-0536",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "secure@intel.com",
"affectedData": [
{
"vendor": "n/a",
"product": "Intel(R) CSME",
"versions": [
{
"status": "affected",
"version": "See provided reference"
}
]
}
]
}
],
"published": "2020-06-15T14:15:10.783",
"references": [
{
"url": "https://security.netapp.com/advisory/ntap-20200611-0006/",
"source": "secure@intel.com"
},
{
"url": "https://support.lenovo.com/de/en/product_security/len-30041",
"source": "secure@intel.com"
},
{
"url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00295.html",
"tags": [
"Vendor Advisory"
],
"source": "secure@intel.com"
},
{
"url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00295.html",
"tags": [
"Vendor Advisory"
],
"source": "secure@intel.com"
},
{
"url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00295.html",
"tags": [
"Vendor Advisory"
],
"source": "secure@intel.com"
},
{
"url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00295.html",
"tags": [
"Vendor Advisory"
],
"source": "secure@intel.com"
},
{
"url": "https://security.netapp.com/advisory/ntap-20200611-0006/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://support.lenovo.com/de/en/product_security/len-30041",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00295.html",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00295.html",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00295.html",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00295.html",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Improper input validation in the DAL subsystem for Intel(R) CSME versions before 11.8.77, 11.12.77, 11.22.77, 12.0.64, 13.0.32,14.0.33 and Intel(R) TXE versions before 3.1.75 and 4.0.25 may allow an unauthenticated user to potentially enable information disclosure via network access."
},
{
"lang": "es",
"value": "Una comprobación de entrada inapropiada en el subsistema DAL para Intel® CSME versiones anteriores a 11.8.77, 11.12.77, 11.22.77, 12.0.64, 13.0.32,14.0.33 e Intel® TXE versiones anteriores a 3.1.75 y 4.0.25, puede permitir a un usuario no autenticado habilitar potencialmente una divulgación de información por medio de un acceso de red"
}
],
"lastModified": "2026-06-17T02:46:00.213",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:intel:converged_security_management_engine_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2CA2E306-9AEC-4767-9738-3EF0B833F896",
"versionEndExcluding": "11.8.77",
"versionStartIncluding": "11.0"
},
{
"criteria": "cpe:2.3:o:intel:converged_security_management_engine_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "299E26BE-7DB3-4D58-9C86-7634ACA11324",
"versionEndExcluding": "11.12.77",
"versionStartIncluding": "11.10"
},
{
"criteria": "cpe:2.3:o:intel:converged_security_management_engine_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E62CE07C-7068-4FE3-9268-0A551D397597",
"versionEndExcluding": "11.22.77",
"versionStartIncluding": "11.20"
},
{
"criteria": "cpe:2.3:o:intel:converged_security_management_engine_firmware:*:*:*:*:*:*:*:undefined",
"vulnerable": true,
"matchCriteriaId": "7A86A849-7161-4EA0-B1CF-4E74A55D2E67",
"versionEndExcluding": "12.0.64",
"versionStartIncluding": "12.0"
},
{
"criteria": "cpe:2.3:o:intel:converged_security_management_engine_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "51B0E191-66BD-49B1-B745-F63006AD2A6F",
"versionEndExcluding": "13.0.32",
"versionStartIncluding": "13.0"
},
{
"criteria": "cpe:2.3:o:intel:converged_security_management_engine_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "004EE62A-979B-4D9B-928D-B2558CE79B4E",
"versionEndExcluding": "14.0.33",
"versionStartIncluding": "14.0"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:intel:trusted_execution_engine_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2ADFD0F7-45EE-4639-AB9D-CA36F7F18181",
"versionEndExcluding": "3.1.75",
"versionStartIncluding": "3.0"
},
{
"criteria": "cpe:2.3:o:intel:trusted_execution_engine_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6D84402A-0018-4632-984C-78F4D85609C3",
"versionEndExcluding": "4.0.25",
"versionStartIncluding": "4.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secure@intel.com"
}