CVE-2020-8705
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Insecure default initialization of resource in Intel(R) Boot Guard in Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE versions before 3.1.80 and 4.0.30, Intel(R) SPS versions before E5_04.01.04.400, E3_04.01.04.200, SoC-X_04.00.04.200 and SoC-A_04.00.04.300 may allow an unauthenticated user to potentially enable escalation of privileges via physical access.
Una inicialización predeterminada no segura del resource en Intel® Boot Guard en Intel® CSME versiones anteriores a 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 y 14.5. 25, Intel® TXE versiones anteriores a 3.1.80 y 4.0.30, Intel® SPS versiones anteriores a E5_04.01.04.400, E3_04.01.04.200, SoC-X_04.00.04.200 y SoC-A_04.00.04. 300, puede habilitar a un usuario no autenticado para permitir potencialmente una escalada de privilegios por medio de un acceso físico
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-02-06 CVE Reserved
- 2020-11-12 CVE Published
- 2024-08-04 CVE Updated
- 2024-09-01 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-1188: Initialization of a Resource with an Insecure Default
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://security.netapp.com/advisory/ntap-20201113-0002 | Third Party Advisory | |
https://security.netapp.com/advisory/ntap-20201113-0004 | Third Party Advisory | |
https://security.netapp.com/advisory/ntap-20201113-0005 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00391 | 2020-11-30 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Intel Search vendor "Intel" | Converged Security And Manageability Engine Search vendor "Intel" for product "Converged Security And Manageability Engine" | < 11.8.80 Search vendor "Intel" for product "Converged Security And Manageability Engine" and version " < 11.8.80" | - |
Affected
| ||||||
Intel Search vendor "Intel" | Converged Security And Manageability Engine Search vendor "Intel" for product "Converged Security And Manageability Engine" | >= 11.12.0 < 11.12.80 Search vendor "Intel" for product "Converged Security And Manageability Engine" and version " >= 11.12.0 < 11.12.80" | - |
Affected
| ||||||
Intel Search vendor "Intel" | Converged Security And Manageability Engine Search vendor "Intel" for product "Converged Security And Manageability Engine" | >= 11.22.0 < 11.22.80 Search vendor "Intel" for product "Converged Security And Manageability Engine" and version " >= 11.22.0 < 11.22.80" | - |
Affected
| ||||||
Intel Search vendor "Intel" | Converged Security And Manageability Engine Search vendor "Intel" for product "Converged Security And Manageability Engine" | >= 12.0 < 12.0.70 Search vendor "Intel" for product "Converged Security And Manageability Engine" and version " >= 12.0 < 12.0.70" | - |
Affected
| ||||||
Intel Search vendor "Intel" | Converged Security And Manageability Engine Search vendor "Intel" for product "Converged Security And Manageability Engine" | >= 13.0 < 13.0.40 Search vendor "Intel" for product "Converged Security And Manageability Engine" and version " >= 13.0 < 13.0.40" | - |
Affected
| ||||||
Intel Search vendor "Intel" | Converged Security And Manageability Engine Search vendor "Intel" for product "Converged Security And Manageability Engine" | >= 13.30.0 < 13.30.10 Search vendor "Intel" for product "Converged Security And Manageability Engine" and version " >= 13.30.0 < 13.30.10" | - |
Affected
| ||||||
Intel Search vendor "Intel" | Converged Security And Manageability Engine Search vendor "Intel" for product "Converged Security And Manageability Engine" | >= 14.0 < 14.0.45 Search vendor "Intel" for product "Converged Security And Manageability Engine" and version " >= 14.0 < 14.0.45" | - |
Affected
| ||||||
Intel Search vendor "Intel" | Trusted Execution Technology Search vendor "Intel" for product "Trusted Execution Technology" | 3.1.80 Search vendor "Intel" for product "Trusted Execution Technology" and version "3.1.80" | - |
Affected
| ||||||
Intel Search vendor "Intel" | Trusted Execution Technology Search vendor "Intel" for product "Trusted Execution Technology" | 4.0.30 Search vendor "Intel" for product "Trusted Execution Technology" and version "4.0.30" | - |
Affected
| ||||||
Intel Search vendor "Intel" | Server Platform Services Search vendor "Intel" for product "Server Platform Services" | sps_e3_04.01.04.200 Search vendor "Intel" for product "Server Platform Services" and version "sps_e3_04.01.04.200" | - |
Affected
| ||||||
Intel Search vendor "Intel" | Server Platform Services Search vendor "Intel" for product "Server Platform Services" | sps_e5_04.01.04.400 Search vendor "Intel" for product "Server Platform Services" and version "sps_e5_04.01.04.400" | - |
Affected
| ||||||
Intel Search vendor "Intel" | Server Platform Services Search vendor "Intel" for product "Server Platform Services" | sps_soc-a_04.00.04.300 Search vendor "Intel" for product "Server Platform Services" and version "sps_soc-a_04.00.04.300" | - |
Affected
| ||||||
Intel Search vendor "Intel" | Server Platform Services Search vendor "Intel" for product "Server Platform Services" | sps_soc-x_04.00.04.200 Search vendor "Intel" for product "Server Platform Services" and version "sps_soc-x_04.00.04.200" | - |
Affected
|