Junglewise Threat Intelligence

CVE-2026-20715: Intel Active Management Technology improper input validation denial of service

CVE-2026-20715 · Severity: info · CVSS 8.2 · Published 2026-08-11

Technologies: Intel Active Management Technology (AMT), Intel Standard Manageability. Vendors: Intel.

Executive brief

Intel Active Management Technology (AMT) and Standard Manageability are firmware management interfaces that enable remote administration of Intel-based systems. An improper input validation flaw allows unauthenticated network attackers to trigger denial of service attacks, making managed systems unavailable. While this does not enable data theft or unauthorized access, it can disrupt critical business operations dependent on these systems remaining available.

Technical details

The vulnerability stems from improper input validation in Intel AMT and Standard Manageability firmware, allowing an unauthenticated network adversary to craft malicious network requests that trigger denial of service conditions. The attack has low complexity and requires no special privileges or user interaction. An attacker can send crafted network packets to the management interface to exhaust resources or crash the firmware, rendering the affected system's management capabilities unavailable. Intel has released firmware updates across multiple processor generations and chipsets to address this issue, with specific patch versions varying by platform (e.g., 14.1.80 for Comet Lake, 15.0.56 for Tiger Lake and newer).

Affected products

  • Intel Active Management Technology (AMT) Multiple generations across Kaby Lake through Sapphire Rapids
  • Intel Standard Manageability Multiple generations across Kaby Lake through Sapphire Rapids

Timeline

  • 2026-08-11: disclosed: Intel security advisory INTEL-SA-01427 released

References

Related threats