Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-12309


Insufficiently protected credentialsin subsystem in some Intel(R) Client SSDs and some Intel(R) Data Center SSDs may allow an unauthenticated user to potentially enable information disclosure via physical access.


Security Impact Summary

This vulnerability carries a MEDIUM severity rating with a CVSS v3.1 score of 4.6, with relatively low complexity without requiring user interaction and does not require pre-existing privileges . The vulnerability impacts confidentiality (data exposure), for affected systems. Impacting 30 products from intel, from intel, from intel and 27 others, organizations running these solutions should prioritize assessment and patching.

Historical Context

Reported in 2020, this vulnerability emerged during an era marked by increased sophistication in supply chain attacks, cloud infrastructure vulnerabilities, and software-as-a-service (SaaS) security challenges. Security practices during this period emphasized zero-trust architectures, container security, and API protection.


Published

2020-11-12T18:15:13.907

Last Modified

2024-11-21T04:59:29.443

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.6 (MEDIUM)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:P/I:N/A:N

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

3.9

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-522

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System intel ssd_pro_6000p_firmware < psf131p Yes
Hardware intel ssd_pro_6000p - No
Operating System intel ssd_pro_5450s_firmware < lhf005p Yes
Hardware intel ssd_pro_5450s - No
Operating System intel ssd_e_5100s_firmware < lhf004e Yes
Hardware intel ssd_e_5100s - No
Operating System intel ssd_pro_5400s_firmware < lbf017p Yes
Hardware intel ssd_pro_5400s - No
Operating System intel ssd_pro_7600p_firmware < 005p Yes
Hardware intel ssd_pro_7600p - No
Operating System intel ssd_760p_firmware < 005c Yes
Hardware intel ssd_760p - No
Operating System intel ssd_e_6100p_firmware < 005e Yes
Hardware intel ssd_e_6100p - No
Operating System intel ssd_660p_firmware < 004c Yes
Hardware intel ssd_660p - No
Operating System intel optane_ssd_905p_firmware < e2010480 Yes
Hardware intel optane_ssd_905p - No
Operating System intel optane_ssd_900p_firmware < e2010480 Yes
Hardware intel optane_ssd_900p - No
Operating System intel ssd_dc_p4510_firmware < vdv10170 Yes
Hardware intel ssd_dc_p4510 - No
Operating System intel ssd_dc_p4610_firmware < vdv10170 Yes
Hardware intel ssd_dc_p4610 - No
Operating System intel ssd_dc_p4800x_firmware < e2010485 Yes
Hardware intel ssd_dc_p4800x - No
Operating System intel ssd_dc_p4801x_firmware < e2010485 Yes
Hardware intel ssd_dc_p4801x - No
Operating System intel ssd_dc_p4101_firmware < 008d Yes
Hardware intel ssd_dc_p4101 - No
Operating System intel ssd_pro_5450s_firmware < lhf0b3p Yes
Hardware intel ssd_pro_5450s - No
Operating System intel ssd_e_5100s_firmware < lhf0ae3 Yes
Hardware intel ssd_e_5100s - No
Operating System intel ssd_pro_5400s_firmware < lsf043p Yes
Hardware intel ssd_pro_5400s - No

References

How SecUtils Interprets This CVE

SecUtils normalizes and enriches National Vulnerability Database (NVD) records by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and providing structured context for security teams. For intel's affected products, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference data to enable rapid vulnerability prioritization and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and security operations.