Insufficient Control Flow Management in Intel Client and Data Center SSDs
CVE-2020-12310
4.6MEDIUM
Key Information:
- Vendor
- Intel
- Vendor
- CVE Published:
- 12 November 2020
Summary
The vulnerability arises from inadequate control flow management in the firmware of certain Intel Client and Data Center SSDs. This loophole may allow an unauthorized user with physical access to the device to potentially exploit the system, leading to information disclosure. Such vulnerabilities highlight the importance of stringent security measures in hardware components.
Affected Version(s)
Intel(R) Client SSDs and some Intel(R) Data Center SSDs See references
References
CVSS V3.1
Score:
4.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved