CVE-2020-8704
6.4
Vector
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.5 / Impact: 5.9
Source: NVD
Description
Race condition in a subsystem in the Intel(R) LMS versions before 2039.1.0.0 may allow a privileged user to potentially enable escalation of privilege via local access.
Affected (13)
Products: Intel: Local Manageability Service · Siemens: Simatic Field Pg M5 Firmware, Simatic Field Pg M6 Firmware, Simatic Ipc427e Firmware, Simatic Ipc477e Firmware, Simatic Ipc477e Pro Firmware, Simatic Ipc527g Firmware, Simatic Ipc547g Firmware, Simatic Ipc627e Firmware, Simatic Ipc647e Firmware, Simatic Ipc677e Firmware, Simatic Ipc847e Firmware, Simatic Itp1000 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2039.1.0.0 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Field Pg M5 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Field Pg M6 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Ipc427e | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Ipc477e | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Ipc477e Pro | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Ipc527g | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Ipc547g | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 25.02.10 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Ipc627e | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 25.02.10 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Ipc647e | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 25.02.10 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Ipc677e | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 25.02.10 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Ipc847e | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Itp1000 | All versions |
References (4)
Source: secure@intel.com
Third Party Advisory
Source: secure@intel.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.