CVE-2020-8744
Improper initialization in subsystem for Intel(R) CSME versions before12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE versions before 4.0.30 Intel(R) SPS versions before E3_05.01.04.200 may allow a privileged user to potentially enable escalation of privilege via local access.
Published:Nov 12, 2020
Last Modified:Nov 21, 2024
EPS:Nov 12, 2020
EPSS Score:0.00157
CVSS Score:7.8
Affected Products
Vendor
Product
Action
Vendor
Intel
Product
Converged Security And Management Engine
Intel
Converged Security And Management Engine
Vendor
Intel
Product
Server Platform Services
Intel
Server Platform Services
Vendor
Intel
Product
Trusted Execution Engine
Intel
Trusted Execution Engine
Vendor
Siemens
Product
Simatic S7-1500
Siemens
Simatic S7-1500
Vendor
Siemens
Product
Simatic S7-1500 Firmware
Siemens
Simatic S7-1500 Firmware
Vendor
Siemens
Product
Simatic S7-1518-4 Pn\/dp Mfp
Siemens
Simatic S7-1518-4 Pn\/dp Mfp
Vendor
Siemens
Product
Simatic S7-1518-4 Pn\/dp Mfp Firmware
Siemens
Simatic S7-1518-4 Pn\/dp Mfp Firmware
Vendor
Siemens
Product
Simatic S7-1518f-4 Pn\/dp Mfp
Siemens
Simatic S7-1518f-4 Pn\/dp Mfp
Vendor
Siemens
Product
Simatic S7-1518f-4 Pn\/dp Mfp Firmware
Siemens
Simatic S7-1518f-4 Pn\/dp Mfp Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
