← Back

CVE-2020-8705

nvd nist
Published: Nov 12, 2020Modified: Nov 21, 2024

JSON object

Loading...
6.8
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.9 / Impact: 5.9
Source: NVD

Description

Insecure default initialization of resource in Intel(R) Boot Guard in Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE versions before 3.1.80 and 4.0.30, Intel(R) SPS versions before E5_04.01.04.400, E3_04.01.04.200, SoC-X_04.00.04.200 and SoC-A_04.00.04.300 may allow an unauthenticated user to potentially enable escalation of privileges via physical access.

Affected (13)

3 products
Trusted Execution Technology
Server Platform Services
Configuration A
7 vulnerable
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Intel
Version 3.1.80
Version 4.0.30
Configuration C
4 vulnerable
Vulnerable SoftwareAffected Versions
Intel
Version sps_e3_04.01.04.200
Version sps_e5_04.01.04.400
Version sps_soc-a_04.00.04.300
Version sps_soc-x_04.00.04.200

References (8)

Source: secure@intel.com
Third Party Advisory
Source: secure@intel.com
Third Party Advisory
Source: secure@intel.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.