The Intel® Converged Security Management Engine (CSME) on the remote host is affected by multiple vulnerabilities in the Intel® Active Management Technology (AMT) function, including the following:
- Out-of-bounds write in IPv6 subsystem for Intel(R) AMT, Intel® ISM versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, and 14.0.45 may allow an unauthenticated user to potentially enable escalation of privileges via network access. (CVE-2020-8752)
- Out-of-bounds read in subsystem for Intel® AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, and 14.0.45 may allow an unauthenticated user to potentially enable information disclosure and/or denial of service via network access. (CVE-2020-8747)
- Out-of-bounds read in subsystem for Intel® AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, and 14.0.45 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access. (CVE-2020-8749)
(Source: Tenable Nessus)
Since this is a critical severity issue, users are strongly advised to immediately apply the solutions to mitigate associated security risks.