Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-24525


Insecure inherited permissions in firmware update tool for some Intel(R) NUCs may allow an authenticated user to potentially enable escalation of privilege via local access.


Published

2020-11-12T19:15:14.833

Last Modified

2024-11-21T05:14:57.590

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

3.9

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-732

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System intel nuc_8_mainstream-g_kit_nuc8i5inh_firmware inwhl357.0036 Yes
Hardware intel nuc_8_mainstream-g_kit_nuc8i5inh - No
Operating System intel nuc_8_mainstream-g_kit_nuc8i7inh_firmware inwhl357.0036 Yes
Hardware intel nuc_8_mainstream-g_kit_nuc8i7inh - No
Operating System intel nuc_8_mainstream-g_mini_pc_nuc8i5inh_firmware inwhl357.0036 Yes
Hardware intel nuc_8_mainstream-g_mini_pc_nuc8i5inh - No
Operating System intel nuc_8_mainstream-g_mini_pc_nuc8i7inh_firmware inwhl357.0036 Yes
Hardware intel nuc_8_mainstream-g_mini_pc_nuc8i7inh - No
Operating System intel nuc_8_pro_board_nuc8i3pnb_firmware pnwhl357.0037 Yes
Hardware intel nuc_8_pro_board_nuc8i3pnb - No
Operating System intel nuc_8_pro_kit_nuc8i3pnh_firmware pnwhl357.0037 Yes
Hardware intel nuc_8_pro_kit_nuc8i3pnh - No
Operating System intel nuc_8_pro_kit_nuc8i3pnk_firmware pnwhl357.0037 Yes
Hardware intel nuc_8_pro_kit_nuc8i3pnk - No
Operating System intel nuc_8_pro_mini_pc_nuc8i3pnk_firmware pnwhl357.0037 Yes
Hardware intel nuc_8_pro_mini_pc_nuc8i3pnk - No
Operating System intel nuc_8_rugged_kit_nuc8cchkr_firmware chaplcel.0049 Yes
Hardware intel nuc_8_rugged_kit_nuc8cchkr - No
Operating System intel nuc_9_pro_kit_nuc9v7qnx_firmware qncflx70.34 Yes
Hardware intel nuc_9_pro_kit_nuc9v7qnx - No
Operating System intel nuc_9_pro_kit_nuc9vxqnx_firmware qncflx70.34 Yes
Hardware intel nuc_9_pro_kit_nuc9vxqnx - No
Operating System intel nuc_board_h27002-400_firmware tybyt10h.86a Yes
Hardware intel nuc_board_h27002-400 - No
Operating System intel nuc_board_h27002-401_firmware tybyt10h.86a Yes
Hardware intel nuc_board_h27002-401 - No
Operating System intel nuc_board_h27002-402_firmware tybyt10h.86a Yes
Hardware intel nuc_board_h27002-402 - No
Operating System intel nuc_board_h27002-404_firmware tybyt10h.86a Yes
Hardware intel nuc_board_h27002-404 - No
Operating System intel nuc_board_h27002-500_firmware tybyt20h.86a Yes
Hardware intel nuc_board_h27002-500 - No
Operating System intel nuc_board_nuc8cchb_firmware chaplcel.0049 Yes
Hardware intel nuc_board_nuc8cchb - No
Operating System intel nuc_kit_h26998-401_firmware tybyt10h.86a Yes
Hardware intel nuc_kit_h26998-401 - No
Operating System intel nuc_kit_h26998-402_firmware tybyt10h.86a Yes
Hardware intel nuc_kit_h26998-402 - No
Operating System intel nuc_kit_h26998-403_firmware tybyt10h.86a Yes
Hardware intel nuc_kit_h26998-403 - No
Operating System intel nuc_kit_h26998-404_firmware tybyt10h.86a Yes
Hardware intel nuc_kit_h26998-404 - No
Operating System intel nuc_kit_h26998-405_firmware tybyt10h.86a Yes
Hardware intel nuc_kit_h26998-405 - No
Operating System intel nuc_kit_h26998-500_firmware tybyt20h.86a Yes
Hardware intel nuc_kit_h26998-500 - No

References