CVE-2020-8709
8.8
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD
Description
Improper authentication in socket services for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.45 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.
Affected (18)
Products: Intel: Server Board S2600wt Firmware, Server System R1000wt Firmware, Server System R2000wt Firmware, Server Board S2600cw, Compute Module Hns2600kp Firmware, Server Board S2600kp Firmware, Compute Module Hns2600tp Firmware, Compute Module S2600tp Firmware, Server Board S1200sp Firmware, Server System Lr1304sp Firmware, Server System Lsvrp Firmware, Server System R1000sp Firmware, Server Board S2600wf Firmware, Server System R1000wf Firmware, Server System R2000wf Firmware, Server Board S2600st Firmware, Compute Module Hns2600bp Firmware, Server Board S2600bp Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.45 |
| Running on/with | Platform Versions |
|---|---|
Intel Server Board S2600wt2 | All versions |
Intel Server Board S2600wt2r | All versions |
Intel Server Board S2600wtt | All versions |
Intel Server Board S2600wttr | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.45 |
| Running on/with | Platform Versions |
|---|---|
Intel Server System R1208wt2gs | All versions |
Intel Server System R1208wt2gsr | All versions |
Intel Server System R1208wttgs | All versions |
Intel Server System R1208wttgsbpp | All versions |
Intel Server System R1208wttgsr | All versions |
Intel Server System R1304wt2gs | All versions |
Intel Server System R1304wt2gsr | All versions |
Intel Server System R1304wttgs | All versions |
Intel Server System R1304wttgsr | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.45 |
| Running on/with | Platform Versions |
|---|---|
Intel Server System R2208wt2ys | All versions |
Intel Server System R2208wt2ysr | All versions |
Intel Server System R2208wttyc1 | All versions |
Intel Server System R2208wttyc1r | All versions |
Intel Server System R2208wttys | All versions |
Intel Server System R2208wttysr | All versions |
Intel Server System R2224wttys | All versions |
Intel Server System R2224wttysr | All versions |
Intel Server System R2308wttys | All versions |
Intel Server System R2308wttysr | All versions |
Intel Server System R2312wttys | All versions |
Intel Server System R2312wttysr | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.45 |
| Running on/with | Platform Versions |
|---|---|
Intel Server Board S2600cw2 | All versions |
Intel Server Board S2600cw2r | All versions |
Intel Server Board S2600cw2s | All versions |
Intel Server Board S2600cw2sr | All versions |
Intel Server Board S2600cwt | All versions |
Intel Server Board S2600cwtr | All versions |
Intel Server Board S2600cwts | All versions |
Intel Server Board S2600cwtsr | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.45 |
| Running on/with | Platform Versions |
|---|---|
Intel Compute Module Hns2600kp | All versions |
Intel Compute Module Hns2600kpf | All versions |
Intel Compute Module Hns2600kpfr | All versions |
Intel Compute Module Hns2600kpr | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.45 |
| Running on/with | Platform Versions |
|---|---|
Intel Server Board S2600kp | All versions |
Intel Server Board S2600kpf | All versions |
Intel Server Board S2600kpfr | All versions |
Intel Server Board S2600kpr | All versions |
Intel Server Board S2600kptr | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.45 |
| Running on/with | Platform Versions |
|---|---|
Intel Compute Module Hns2600tp | All versions |
Intel Compute Module Hns2600tp24r | All versions |
Intel Compute Module Hns2600tp24sr | All versions |
Intel Compute Module Hns2600tpf | All versions |
Intel Compute Module Hns2600tpfr | All versions |
Intel Compute Module Hns2600tpr | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.45 |
| Running on/with | Platform Versions |
|---|---|
Intel Server Board S2600tp | All versions |
Intel Server Board S2600tpf | All versions |
Intel Server Board S2600tpfr | All versions |
Intel Server Board S2600tpr | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.45 |
| Running on/with | Platform Versions |
|---|---|
Intel Server Board S1200spl | All versions |
Intel Server Board S1200splr | All versions |
Intel Server Board S1200spo | All versions |
Intel Server Board S1200spor | All versions |
Intel Server Board S1200sps | All versions |
Intel Server Board S1200spsr | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.45 |
| Running on/with | Platform Versions |
|---|---|
Intel Server System Lr1304spcfg1 | All versions |
Intel Server System Lr1304spcfg1r | All versions |
Intel Server System Lr1304spcfsgx1 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.45 |
| Running on/with | Platform Versions |
|---|---|
Intel Server System Lsvrp4304es6xx1 | All versions |
Intel Server System Lsvrp4304es6xxr | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.45 |
| Running on/with | Platform Versions |
|---|---|
Intel Server System R1208sposhor | All versions |
Intel Server System R1208sposhorr | All versions |
Intel Server System R1304sposhbn | All versions |
Intel Server System R1304sposhbnr | All versions |
Intel Server System R1304sposhor | All versions |
Intel Server System R1304sposhorr | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.45 |
| Running on/with | Platform Versions |
|---|---|
Intel Server Board S2600wf0 | All versions |
Intel Server Board S2600wf0r | All versions |
Intel Server Board S2600wfq | All versions |
Intel Server Board S2600wfqr | All versions |
Intel Server Board S2600wft | All versions |
Intel Server Board S2600wftr | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.45 |
| Running on/with | Platform Versions |
|---|---|
Intel Server System Lnetcnt3y | All versions |
Intel Server System Mcb2208wfaf4 | All versions |
Intel Server System Mcb2208wfaf5 | All versions |
Intel Server System Mcb2208wfaf6 | All versions |
Intel Server System Mcb2208wfhy2 | All versions |
Intel Server System Nb2208wfqnfvi | All versions |
Intel Server System R1208wfqysr | All versions |
Intel Server System R1208wftys | All versions |
Intel Server System R1208wftysr | All versions |
Intel Server System R1304wf0ys | All versions |
Intel Server System R1304wf0ysr | All versions |
Intel Server System R1304wftys | All versions |
Intel Server System R1304wftysr | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.45 |
| Running on/with | Platform Versions |
|---|---|
Intel Server System R2208wf0zs | All versions |
Intel Server System R2208wf0zsr | All versions |
Intel Server System R2208wfqzs | All versions |
Intel Server System R2208wfqzsr | All versions |
Intel Server System R2208wftzs | All versions |
Intel Server System R2208wftzsr | All versions |
Intel Server System R2224wfqzs | All versions |
Intel Server System R2224wftzs | All versions |
Intel Server System R2224wftzsr | All versions |
Intel Server System R2308wftzs | All versions |
Intel Server System R2308wftzsr | All versions |
Intel Server System R2312wf0np | All versions |
Intel Server System R2312wf0npr | All versions |
Intel Server System R2312wfqzs | All versions |
Intel Server System R2312wftzs | All versions |
Intel Server System R2312wftzsr | All versions |
Intel Server System Vrn2208waf6 | All versions |
Intel Server System Vrn2208wfaf81 | All versions |
Intel Server System Vrn2208wfaf82 | All versions |
Intel Server System Vrn2208wfaf83 | All versions |
Intel Server System Vrn2208wfhy6 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.45 |
| Running on/with | Platform Versions |
|---|---|
Intel Server Board S2600stb | All versions |
Intel Server Board S2600stbr | All versions |
Intel Server Board S2600stq | All versions |
Intel Server Board S2600stqr | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.45 |
| Running on/with | Platform Versions |
|---|---|
Intel Compute Module Hns2600bpb | All versions |
Intel Compute Module Hns2600bpb24 | All versions |
Intel Compute Module Hns2600bpb24r | All versions |
Intel Compute Module Hns2600bpblc | All versions |
Intel Compute Module Hns2600bpblc24 | All versions |
Intel Compute Module Hns2600bpblc24r | All versions |
Intel Compute Module Hns2600bpblcr | All versions |
Intel Compute Module Hns2600bpbr | All versions |
Intel Compute Module Hns2600bpq | All versions |
Intel Compute Module Hns2600bpq24 | All versions |
Intel Compute Module Hns2600bpq24r | All versions |
Intel Compute Module Hns2600bpqr | All versions |
Intel Compute Module Hns2600bps | All versions |
Intel Compute Module Hns2600bps24 | All versions |
Intel Compute Module Hns2600bps24r | All versions |
Intel Compute Module Hns2600bpsr | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.45 |
| Running on/with | Platform Versions |
|---|---|
Intel Server Board S2600bpb | All versions |
Intel Server Board S2600bpbr | All versions |
Intel Server Board S2600bpq | All versions |
Intel Server Board S2600bpqr | All versions |
Intel Server Board S2600bps | All versions |
Intel Server Board S2600bpsr | All versions |
References (4)
Source: secure@intel.com
Third Party Advisory
Source: secure@intel.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.