Privilege Escalation Vulnerability in Intel CSME Software
CVE-2020-24516

6.8MEDIUM

Key Information:

Vendor
Intel
Vendor
CVE Published:
9 June 2021

Summary

A vulnerability exists in Intel's CSME software that may allow an unauthenticated user to modify data that is assumed to be immutable. This could potentially lead to privilege escalation through physical access to the affected systems. To mitigate the risks associated with this issue, it is essential for users to apply the latest firmware updates provided by Intel, which address this security flaw and improve overall system integrity.

Affected Version(s)

Intel(R) CSME versions before 13.0.47, 13.30.17, 14.1.53, 14.5.32, 15.0.22

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.