Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-0545


Integer overflow in subsystem for Intel(R) CSME versions before 11.8.77, 11.12.77, 11.22.77 and Intel(R) TXE versions before 3.1.75, 4.0.25 and Intel(R) Server Platform Services (SPS) versions before SPS_E5_04.01.04.380.0, SPS_SoC-X_04.00.04.128.0, SPS_SoC-A_04.00.04.211.0, SPS_E3_04.01.04.109.0, SPS_E3_04.08.04.070.0 may allow a privileged user to potentially enable denial of service via local access.


Published

2020-06-15T14:15:11.267

Last Modified

2024-11-21T04:53:42.817

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.4 (MEDIUM)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:N/I:N/A:P

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

3.9

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-190

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System intel converged_security_management_engine_firmware < 11.8.77 Yes
Operating System intel converged_security_management_engine_firmware < 11.12.77 Yes
Operating System intel converged_security_management_engine_firmware < 11.22.77 Yes
Application intel server_platform_services < sps_e3_04.01.04.109.0 Yes
Application intel server_platform_services < sps_e3_04.08.04.070.0 Yes
Application intel server_platform_services < sps_e5_04.01.04.380.0 Yes
Application intel server_platform_services < sps_soc-a_04.00.04.211.0 Yes
Application intel server_platform_services < sps_soc-x_04.00.04.128.0 Yes
Operating System intel trusted_execution_engine < 3.1.75 Yes
Operating System intel trusted_execution_engine < 4.0.25 Yes

References