Insufficient Control Flow Management in Intel Client and Data Center SSDs
CVE-2020-12310

4.6MEDIUM

Key Information:

Vendor
Intel
Vendor
CVE Published:
12 November 2020

Summary

The vulnerability arises from inadequate control flow management in the firmware of certain Intel Client and Data Center SSDs. This loophole may allow an unauthorized user with physical access to the device to potentially exploit the system, leading to information disclosure. Such vulnerabilities highlight the importance of stringent security measures in hardware components.

Affected Version(s)

Intel(R) Client SSDs and some Intel(R) Data Center SSDs See references

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.