CVE-2020-24511
published 2021-06-09CVE-2020-24511: Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local…
PriorityP423medium6.5CVSS 3.1
AVLACLPRLUINSCCHINAN
EPSS
0.40%
32.9th percentile
Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | intel-microcode | < intel-microcode 3.20210608.1 (bookworm) | intel-microcode 3.20210608.1 (bookworm) |
| intel | microcode | < 20210608 | 20210608 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat5.6MEDIUM
vendor_ubuntu5.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens Industrial Products Intel CPUs (Update G)
cisa_ics·2022-09-13
Siemens Industrial Products Intel CPUs (Update G)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens Industrial Products Intel CPUs (Update G)
Last RevisedDecember 15, 2022
Alert CodeICSA-21-222-05
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.5
- ATTENTION: Low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC, SINUMERIK
- Vulnerabilities: Missing Encryption of Sensitive Data
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the advisory update titled ICSA-21-222-05 Siemens Industrial Products Intel CPU (Update F) that was published September 13, 2022, to the ICS webpage on www.cisa.gov/ics.
## 3. RISK EVALUATION
Successful exploitation of these vul
Ubuntu
Intel Microcode vulnerabilities
vendor_ubuntu·2021-06-09·CVSS 5.6
CVE-2020-24512 [MEDIUM] Intel Microcode vulnerabilities
Title: Intel Microcode vulnerabilities
Summary: Several security issues were fixed in Intel Microcode.
It was discovered that some Intel processors may not properly invalidate
cache entries used by Intel Virtualization Technology for Directed I/O
(VT-d). This may allow a local user to perform a privilege escalation
attack. (CVE-2020-24489)
Joseph Nuzman discovered that some Intel processors may not properly apply
EIBRS mitigations (originally developed for CVE-2017-5715) and hence may
allow unauthorized memory reads via sidechannel attacks. A local attacker
could use this to expose sensitive information, including kernel
memory. (CVE-2020-24511)
Travis Downs discovered that some Intel processors did not properly flush
cache-lines for trivial-data values. This may allow an unauthorized
Red Hat
hw: improper isolation of shared resources in some Intel Processors
vendor_redhat·2021-06-08·CVSS 5.6
CVE-2020-24511 [MEDIUM] CWE-200 hw: improper isolation of shared resources in some Intel Processors
hw: improper isolation of shared resources in some Intel Processors
Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Microcode misconfiguration in some Intel processors may cause EIBRS mitigation (CVE-2017-5715) to be incomplete. As a consequence, this issue may allow an authenticated user to potentially enable information disclosure via local access.
Debian
CVE-2020-24511: intel-microcode - Improper isolation of shared resources in some Intel(R) Processors may allow an ...
vendor_debian·2020·CVSS 6.5
CVE-2020-24511 [MEDIUM] CVE-2020-24511: intel-microcode - Improper isolation of shared resources in some Intel(R) Processors may allow an ...
Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20210608.1)
bullseye: resolved (fixed in 3.20210608.1)
forky: resolved (fixed in 3.20210608.1)
sid: resolved (fixed in 3.20210608.1)
trixie: resolved (fixed in 3.20210608.1)
GHSA
GHSA-47r2-gqx8-p99j: Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via lo
ghsa_unreviewed·2022-05-24
CVE-2020-24511 [MEDIUM] CWE-668 GHSA-47r2-gqx8-p99j: Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via lo
Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
OSV
intel-microcode vulnerabilities
osv·2021-06-09·CVSS 5.6
CVE-2020-24489 [MEDIUM] intel-microcode vulnerabilities
intel-microcode vulnerabilities
It was discovered that some Intel processors may not properly invalidate
cache entries used by Intel Virtualization Technology for Directed I/O
(VT-d). This may allow a local user to perform a privilege escalation
attack. (CVE-2020-24489)
Joseph Nuzman discovered that some Intel processors may not properly apply
EIBRS mitigations (originally developed for CVE-2017-5715) and hence may
allow unauthorized memory reads via sidechannel attacks. A local attacker
could use this to expose sensitive information, including kernel
memory. (CVE-2020-24511)
Travis Downs discovered that some Intel processors did not properly flush
cache-lines for trivial-data values. This may allow an unauthorized user to
infer the presence of these trivial-data-cache-lines via timing
OSV
CVE-2020-24511: Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via lo
osv·2021-06-09·CVSS 6.5
CVE-2020-24511 [MEDIUM] CVE-2020-24511: Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via lo
Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://cert-portal.siemens.com/productcert/pdf/ssa-309571.pdfhttps://lists.debian.org/debian-lts-announce/2021/07/msg00022.htmlhttps://security.netapp.com/advisory/ntap-20210611-0005/https://www.debian.org/security/2021/dsa-4934https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00464.htmlhttps://cert-portal.siemens.com/productcert/pdf/ssa-309571.pdfhttps://lists.debian.org/debian-lts-announce/2021/07/msg00022.htmlhttps://security.netapp.com/advisory/ntap-20210611-0005/https://www.debian.org/security/2021/dsa-4934https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00464.html
2021-06-09
Published