Improper Input Validation in Intel(R) CSME Products
CVE-2020-8756
6.7MEDIUM
Summary
Improper input validation in the Intel(R) CSME subsystem across specific versions allows a privileged user to potentially escalate privileges through local access. This raises concerns regarding the security of systems utilizing affected CSME versions, making it essential for users to update to the latest versions to mitigate potential risks. The vulnerability highlights the importance of rigorous input validation mechanisms in maintaining system integrity and security.
Affected Version(s)
Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45
References
CVSS V3.1
Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved