ID

VAR-202006-0255


CVE

CVE-2020-0540


TITLE

Intel(R) AMT Vulnerability regarding inadequate protection of credentials in

Trust: 0.8

sources: JVNDB: JVNDB-2020-006793

DESCRIPTION

Insufficiently protected credentials in Intel(R) AMT versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable information disclosure via network access. Intel(R) AMT Exists in an inadequate protection of credentials.Information may be obtained. Intel Active Management Technology (AMT) is a set of hardware-based computer remote active management technology software developed by Intel Corporation. A remote attacker could exploit this vulnerability to obtain information. The following products and versions are affected: Intel AMT versions prior to 11.8.77, versions prior to 11.12.77, versions prior to 11.22.77, and versions prior to 12.0.64

Trust: 1.71

sources: NVD: CVE-2020-0540 // JVNDB: JVNDB-2020-006793 // VULHUB: VHN-161974

AFFECTED PRODUCTS

vendor:intelmodel:active management technologyscope:gteversion:11.0

Trust: 1.0

vendor:intelmodel:active management technologyscope:ltversion:11.22.77

Trust: 1.0

vendor:intelmodel:active management technologyscope:gteversion:11.20

Trust: 1.0

vendor:intelmodel:active management technologyscope:ltversion:12.0.64

Trust: 1.0

vendor:intelmodel:active management technologyscope:gteversion:12.0

Trust: 1.0

vendor:intelmodel:active management technologyscope:gteversion:11.10

Trust: 1.0

vendor:intelmodel:active management technologyscope:ltversion:11.12.77

Trust: 1.0

vendor:intelmodel:active management technologyscope:ltversion:11.8.77

Trust: 1.0

vendor:intelmodel:active management technologyscope:eqversion:11.12.77

Trust: 0.8

vendor:intelmodel:active management technologyscope:eqversion:11.22.77

Trust: 0.8

vendor:intelmodel:active management technologyscope:eqversion:11.8.77

Trust: 0.8

vendor:intelmodel:active management technologyscope:eqversion:12.0.64

Trust: 0.8

sources: JVNDB: JVNDB-2020-006793 // NVD: CVE-2020-0540

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-0540
value: HIGH

Trust: 1.0

NVD: JVNDB-2020-006793
value: HIGH

Trust: 0.8

CNNVD: CNNVD-202006-752
value: HIGH

Trust: 0.6

VULHUB: VHN-161974
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2020-0540
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

NVD: JVNDB-2020-006793
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

VULHUB: VHN-161974
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2020-0540
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.1

Trust: 1.0

NVD: JVNDB-2020-006793
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULHUB: VHN-161974 // JVNDB: JVNDB-2020-006793 // CNNVD: CNNVD-202006-752 // NVD: CVE-2020-0540

PROBLEMTYPE DATA

problemtype:CWE-522

Trust: 1.9

sources: VULHUB: VHN-161974 // JVNDB: JVNDB-2020-006793 // NVD: CVE-2020-0540

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202006-752

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202006-752

CONFIGURATIONS

sources: JVNDB: JVNDB-2020-006793

PATCH

title:INTEL-SA-00295url:https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00295.html

Trust: 0.8

title:Intel AMT Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=122456

Trust: 0.6

sources: JVNDB: JVNDB-2020-006793 // CNNVD: CNNVD-202006-752

EXTERNAL IDS

db:NVDid:CVE-2020-0540

Trust: 2.5

db:LENOVOid:LEN-30041

Trust: 1.7

db:JVNid:JVNVU98979613

Trust: 0.8

db:JVNDBid:JVNDB-2020-006793

Trust: 0.8

db:CNNVDid:CNNVD-202006-752

Trust: 0.7

db:AUSCERTid:ESB-2020.1991.2

Trust: 0.6

db:AUSCERTid:ESB-2020.1991

Trust: 0.6

db:VULHUBid:VHN-161974

Trust: 0.1

sources: VULHUB: VHN-161974 // JVNDB: JVNDB-2020-006793 // CNNVD: CNNVD-202006-752 // NVD: CVE-2020-0540

REFERENCES

url:https://security.netapp.com/advisory/ntap-20200611-0007/

Trust: 1.7

url:https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00295.html

Trust: 1.7

url:https://support.lenovo.com/de/en/product_security/len-30041

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2020-0540

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2020-0540

Trust: 0.8

url:https://jvn.jp/vu/jvnvu98979613/

Trust: 0.8

url:https://www.auscert.org.au/bulletins/esb-2020.1991/

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2020.1991.2/

Trust: 0.6

url:https://vigilance.fr/vulnerability/intel-csme-sps-txe-amt-ism-dal-multiple-vulnerabilities-32545

Trust: 0.6

url:https://support.lenovo.com/us/en/product_security/len-30041

Trust: 0.6

sources: VULHUB: VHN-161974 // JVNDB: JVNDB-2020-006793 // CNNVD: CNNVD-202006-752 // NVD: CVE-2020-0540

SOURCES

db:VULHUBid:VHN-161974
db:JVNDBid:JVNDB-2020-006793
db:CNNVDid:CNNVD-202006-752
db:NVDid:CVE-2020-0540

LAST UPDATE DATE

2024-11-23T21:14:48.528000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-161974date:2020-07-22T00:00:00
db:JVNDBid:JVNDB-2020-006793date:2020-07-17T00:00:00
db:CNNVDid:CNNVD-202006-752date:2021-05-24T00:00:00
db:NVDid:CVE-2020-0540date:2024-11-21T04:53:42.090

SOURCES RELEASE DATE

db:VULHUBid:VHN-161974date:2020-06-15T00:00:00
db:JVNDBid:JVNDB-2020-006793date:2020-07-17T00:00:00
db:CNNVDid:CNNVD-202006-752date:2020-06-09T00:00:00
db:NVDid:CVE-2020-0540date:2020-06-15T14:15:11.017