CVE-2020-12336
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
Insecure default variable initialization in firmware for some Intel(R) NUCs may allow an authenticated user to potentially enable escalation of privilege via local access.
Affected (23)
Products: Intel: Nuc 8 Mainstream G Kit Nuc8i5inh Firmware, Nuc 8 Mainstream G Kit Nuc8i7inh Firmware, Nuc 8 Mainstream G Mini Pc Nuc8i5inh Firmware, Nuc 8 Mainstream G Mini Pc Nuc8i7inh Firmware, Nuc 8 Pro Board Nuc8i3pnb Firmware, Nuc 8 Pro Kit Nuc8i3pnh Firmware, Nuc 8 Pro Kit Nuc8i3pnk Firmware, Nuc 8 Pro Mini Pc Nuc8i3pnk Firmware, Nuc 8 Rugged Kit Nuc8cchkr Firmware, Nuc 9 Pro Kit Nuc9v7qnx Firmware, Nuc 9 Pro Kit Nuc9vxqnx Firmware, Nuc Board H27002 400 Firmware, Nuc Board H27002 401 Firmware, Nuc Board H27002 402 Firmware, Nuc Board H27002 404 Firmware, Nuc Board H27002 500 Firmware, Nuc Board Nuc8cchb Firmware, Nuc Kit H26998 401 Firmware, Nuc Kit H26998 402 Firmware, Nuc Kit H26998 403 Firmware, Nuc Kit H26998 404 Firmware, Nuc Kit H26998 405 Firmware, Nuc Kit H26998 500 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version inwhl357.0036 |
| Running on/with | Platform Versions |
|---|---|
Intel Nuc 8 Mainstream G Kit Nuc8i5inh | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version inwhl357.0036 |
| Running on/with | Platform Versions |
|---|---|
Intel Nuc 8 Mainstream G Kit Nuc8i7inh | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version inwhl357.0036 |
| Running on/with | Platform Versions |
|---|---|
Intel Nuc 8 Mainstream G Mini Pc Nuc8i5inh | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version inwhl357.0036 |
| Running on/with | Platform Versions |
|---|---|
Intel Nuc 8 Mainstream G Mini Pc Nuc8i7inh | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version pnwhl357.0037 |
| Running on/with | Platform Versions |
|---|---|
Intel Nuc 8 Pro Board Nuc8i3pnb | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version pnwhl357.0037 |
| Running on/with | Platform Versions |
|---|---|
Intel Nuc 8 Pro Kit Nuc8i3pnh | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version pnwhl357.0037 |
| Running on/with | Platform Versions |
|---|---|
Intel Nuc 8 Pro Kit Nuc8i3pnk | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version pnwhl357.0037 |
| Running on/with | Platform Versions |
|---|---|
Intel Nuc 8 Pro Mini Pc Nuc8i3pnk | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Version chaplcel.0049 |
| Running on/with | Platform Versions |
|---|---|
Intel Nuc 8 Rugged Kit Nuc8cchkr | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Version qncflx70.34 |
| Running on/with | Platform Versions |
|---|---|
Intel Nuc 9 Pro Kit Nuc9v7qnx | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Version qncflx70.34 |
| Running on/with | Platform Versions |
|---|---|
Intel Nuc 9 Pro Kit Nuc9vxqnx | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Version tybyt10h.86a |
| Running on/with | Platform Versions |
|---|---|
Intel Nuc Board H27002 400 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Version tybyt10h.86a |
| Running on/with | Platform Versions |
|---|---|
Intel Nuc Board H27002 401 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Version tybyt10h.86a |
| Running on/with | Platform Versions |
|---|---|
Intel Nuc Board H27002 402 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Version tybyt10h.86a |
| Running on/with | Platform Versions |
|---|---|
Intel Nuc Board H27002 404 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Version tybyt20h.86a |
| Running on/with | Platform Versions |
|---|---|
Intel Nuc Board H27002 500 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Version chaplcel.0049 |
| Running on/with | Platform Versions |
|---|---|
Intel Nuc Board Nuc8cchb | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Version tybyt10h.86a |
| Running on/with | Platform Versions |
|---|---|
Intel Nuc Kit H26998 401 | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Version tybyt10h.86a |
| Running on/with | Platform Versions |
|---|---|
Intel Nuc Kit H26998 402 | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Version tybyt10h.86a |
| Running on/with | Platform Versions |
|---|---|
Intel Nuc Kit H26998 403 | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Version tybyt10h.86a |
| Running on/with | Platform Versions |
|---|---|
Intel Nuc Kit H26998 404 | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Version tybyt10h.86a |
| Running on/with | Platform Versions |
|---|---|
Intel Nuc Kit H26998 405 | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Version tybyt20h.86a |
| Running on/with | Platform Versions |
|---|---|
Intel Nuc Kit H26998 500 | All versions |
References (2)
Source: secure@intel.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.