« Volver al listado

CVE-2020-0597

Estado: ModificadaAlta (7.5)—

Out-of-bounds read in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 14.0.33 may allow an unauthenticated user to potentially enable denial of service via network access.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-0597",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "secure@intel.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "Intel(R) AMT and Intel(R) ISM",
          "versions": [
            {
              "status": "affected",
              "version": "See provided reference"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-06-15T14:15:11.660",
  "references": [
    {
      "url": "https://security.netapp.com/advisory/ntap-20200611-0007/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "secure@intel.com"
    },
    {
      "url": "https://support.lenovo.com/de/en/product_security/len-30041",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "secure@intel.com"
    },
    {
      "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00295.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secure@intel.com"
    },
    {
      "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00295.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secure@intel.com"
    },
    {
      "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00295.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secure@intel.com"
    },
    {
      "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00295.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secure@intel.com"
    },
    {
      "url": "https://www.kb.cert.org/vuls/id/257161",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "secure@intel.com"
    },
    {
      "url": "https://www.synology.com/security/advisory/Synology_SA_20_15",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "secure@intel.com"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20200611-0007/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.lenovo.com/de/en/product_security/len-30041",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00295.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00295.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00295.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00295.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.kb.cert.org/vuls/id/257161",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.synology.com/security/advisory/Synology_SA_20_15",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-125"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Out-of-bounds read in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 14.0.33 may allow an unauthenticated user to potentially enable denial of service via network access."
    },
    {
      "lang": "es",
      "value": "Una lectura fuera de límites en el subsistema IPv6 en Intel® AMT e Intel® ISM versiones anteriores a 14.0.33, puede permitir a un usuario no autenticado habilitar potencialmente una denegación de servicio por medio de un acceso de red"
    }
  ],
  "lastModified": "2026-06-17T02:46:07.647",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:intel:software_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "64F972AA-4420-4983-B0DF-085CAE58E51D",
              "versionEndIncluding": "11.8.76",
              "versionStartIncluding": "11.0"
            },
            {
              "criteria": "cpe:2.3:a:intel:software_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "49B19589-FF5A-4908-8317-6E2DDDF40DD0",
              "versionEndIncluding": "11.11.76",
              "versionStartIncluding": "11.10"
            },
            {
              "criteria": "cpe:2.3:a:intel:software_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "89D1B44A-5783-480A-BB32-2A96012B5C2A",
              "versionEndIncluding": "11.22.76",
              "versionStartIncluding": "11.20"
            },
            {
              "criteria": "cpe:2.3:a:intel:software_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2184BE20-E41F-4FE9-9897-C9BB527B45D0",
              "versionEndIncluding": "12.0.63",
              "versionStartIncluding": "12.0"
            },
            {
              "criteria": "cpe:2.3:a:intel:software_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "350276F5-E8F5-4261-B7C5-7662F21782D0",
              "versionEndIncluding": "13.0.31",
              "versionStartIncluding": "13.0"
            },
            {
              "criteria": "cpe:2.3:a:intel:software_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E9E73D17-715D-4BA9-9E45-FBC09587973E",
              "versionEndIncluding": "14.0.32",
              "versionStartIncluding": "14.0"
            },
            {
              "criteria": "cpe:2.3:o:intel:active_management_technology_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DB0A7300-2C3E-493F-9FC7-95376E2730B3",
              "versionEndIncluding": "11.8.76",
              "versionStartIncluding": "11.0"
            },
            {
              "criteria": "cpe:2.3:o:intel:active_management_technology_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F5BFB6EB-4B20-49A3-9307-B905C419554E",
              "versionEndIncluding": "11.11.76",
              "versionStartIncluding": "11.10"
            },
            {
              "criteria": "cpe:2.3:o:intel:active_management_technology_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B5538026-BEA0-4764-94BE-D09CFE74FCC5",
              "versionEndIncluding": "11.22.76",
              "versionStartIncluding": "11.20"
            },
            {
              "criteria": "cpe:2.3:o:intel:active_management_technology_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B221B839-F12B-41D3-BB8F-CF552FFA11F3",
              "versionEndIncluding": "12.0.63",
              "versionStartIncluding": "12.0"
            },
            {
              "criteria": "cpe:2.3:o:intel:active_management_technology_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DBCF8CDE-05FD-48F7-BE29-68984E401B28",
              "versionEndIncluding": "13.0.31",
              "versionStartIncluding": "13.0"
            },
            {
              "criteria": "cpe:2.3:o:intel:active_management_technology_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DE4AF2ED-BFCB-4DCB-8E9A-CFEF652EDD11",
              "versionEndIncluding": "14.0.32",
              "versionStartIncluding": "14.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secure@intel.com"
}