Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-8705


Insecure default initialization of resource in Intel(R) Boot Guard in Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE versions before 3.1.80 and 4.0.30, Intel(R) SPS versions before E5_04.01.04.400, E3_04.01.04.200, SoC-X_04.00.04.200 and SoC-A_04.00.04.300 may allow an unauthenticated user to potentially enable escalation of privileges via physical access.


Published

2020-11-12T18:15:16.847

Last Modified

2024-11-21T05:39:17.910

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.8 (MEDIUM)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

3.9

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-1188

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application intel converged_security_and_manageability_engine < 11.8.80 Yes
Application intel converged_security_and_manageability_engine < 11.12.80 Yes
Application intel converged_security_and_manageability_engine < 11.22.80 Yes
Application intel converged_security_and_manageability_engine < 12.0.70 Yes
Application intel converged_security_and_manageability_engine < 13.0.40 Yes
Application intel converged_security_and_manageability_engine < 13.30.10 Yes
Application intel converged_security_and_manageability_engine < 14.0.45 Yes
Application intel trusted_execution_technology 3.1.80 Yes
Application intel trusted_execution_technology 4.0.30 Yes
Application intel server_platform_services sps_e3_04.01.04.200 Yes
Application intel server_platform_services sps_e5_04.01.04.400 Yes
Application intel server_platform_services sps_soc-a_04.00.04.300 Yes
Application intel server_platform_services sps_soc-x_04.00.04.200 Yes

References