Intel has fixed two critical vulnerabilities (CVE-2020-0594, CVE-2020-0595) in the implementations of Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM), which provide interfaces for monitoring and managing hardware. The issues have been assigned the highest severity level (9.8 out of 10 CVSS) because the vulnerabilities allow an unauthenticated attacker to access remote management functions over the network by sending specially crafted IPv6 packets. The problem only occurs when AMT is configured to allow IPv6 access, which is disabled by default. The vulnerabilities have been fixed in firmware updates 11.8.77, 11.12.77, 11.22.77, and 12.0.64.
It is worth noting that modern Intel chipsets are equipped with a separate Management Engine microprocessor that operates independently of the CPU and operating system. The Management Engine is responsible for executing tasks that need to be separated from the OS, such as processing protected content (DRM), implementing Trusted Platform Module (TPM) modules, and providing low-level interfaces for monitoring and managing hardware. The AMT interface allows access to power management functions, traffic monitoring, BIOS settings changes, firmware updates, disk wiping, remote boot of a new OS (emulating a USB drive from which it can boot), console redirection (Serial Over LAN and KVM over the network), etc. The provided interfaces are sufficient to conduct attacks typically requiring physical access to the system, allowing for actions such as booting a Live system and making changes to the primary system from there.
Source: opennet.ru
