CVE-2020-0543Incomplete Cleanup in Siemens Simatic Field PG M5 Firmware

Severity
5.5MEDIUMNVD
EPSS
0.5%
top 34.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 15
Latest updateSep 19

Description

Incomplete cleanup from specific special register read operations in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages17 packages

Also affects: Fedora 31, 32, Ubuntu Linux 12.04, 14.04, 16.04, 18.04, 19.10, 20.04

🔴Vulnerability Details

10
OSV
xen vulnerabilities2022-09-19
GHSA
GHSA-8gvr-7c6p-jfwg: Incomplete cleanup from specific special register read operations in some Intel(R) Processors may allow an authenticated user to potentially enable in2022-05-24
CVEList
CVE-2020-0543: Incomplete cleanup from specific special register read operations in some Intel(R) Processors may allow an authenticated user to potentially enable in2020-06-15
OSV
CVE-2020-0543: Incomplete cleanup from specific special register read operations in some Intel(R) Processors may allow an authenticated user to potentially enable in2020-06-15
OSV
linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-gcp, linux-gke-4.15, linux-hwe, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities2020-06-11

📋Vendor Advisories

12
Ubuntu
Xen vulnerabilities2022-09-19
Ubuntu
Linux kernel vulnerabilities2020-06-11
Ubuntu
Linux kernel vulnerabilities2020-06-11
Ubuntu
Linux kernel vulnerabilities2020-06-10
Ubuntu
Linux kernel vulnerabilities2020-06-10

💬Community

3
Bugzilla
CVE-2020-0543 kernel: hw: Special Register Buffer Data Sampling (SRBDS) [fedora-all]2020-06-09
Bugzilla
CVE-2020-0543 microcode_ctl: hw: Special Register Buffer Data Sampling (SRBDS) [fedora-all]2020-06-09
Bugzilla
CVE-2020-0543 hw: Special Register Buffer Data Sampling (SRBDS)2020-04-23
CVE-2020-0543 — Incomplete Cleanup in Siemens | cvebase