CVE-2020-24513
published 2021-06-09CVE-2020-24513: Domain-bypass transient execution vulnerability in some Intel Atom(R) Processors may allow an authenticated user to potentially enable information disclosure…
PriorityP425medium6.5CVSS 3.1
AVLACLPRLUINSCCHINAN
EPSS
0.47%
37.8th percentile
Domain-bypass transient execution vulnerability in some Intel Atom(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | intel-microcode | < intel-microcode 3.20210608.1 (bookworm) | intel-microcode 3.20210608.1 (bookworm) |
| siemens | simatic_et_200sp_open_controller_firmware | < 0209_0105 | 0209_0105 |
| siemens | simatic_ipc127e_firmware | < 21.01.07 | 21.01.07 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu5.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens Industrial Products Intel CPUs (Update G)
cisa_ics·2022-09-13
Siemens Industrial Products Intel CPUs (Update G)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens Industrial Products Intel CPUs (Update G)
Last RevisedDecember 15, 2022
Alert CodeICSA-21-222-05
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.5
- ATTENTION: Low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC, SINUMERIK
- Vulnerabilities: Missing Encryption of Sensitive Data
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the advisory update titled ICSA-21-222-05 Siemens Industrial Products Intel CPU (Update F) that was published September 13, 2022, to the ICS webpage on www.cisa.gov/ics.
## 3. RISK EVALUATION
Successful exploitation of these vul
Ubuntu
Intel Microcode vulnerabilities
vendor_ubuntu·2021-06-09·CVSS 5.6
CVE-2020-24512 [MEDIUM] Intel Microcode vulnerabilities
Title: Intel Microcode vulnerabilities
Summary: Several security issues were fixed in Intel Microcode.
It was discovered that some Intel processors may not properly invalidate
cache entries used by Intel Virtualization Technology for Directed I/O
(VT-d). This may allow a local user to perform a privilege escalation
attack. (CVE-2020-24489)
Joseph Nuzman discovered that some Intel processors may not properly apply
EIBRS mitigations (originally developed for CVE-2017-5715) and hence may
allow unauthorized memory reads via sidechannel attacks. A local attacker
could use this to expose sensitive information, including kernel
memory. (CVE-2020-24511)
Travis Downs discovered that some Intel processors did not properly flush
cache-lines for trivial-data values. This may allow an unauthorized
Red Hat
hw: information disclosure on some Intel Atom processors
vendor_redhat·2021-06-08·CVSS 6.5
CVE-2020-24513 [MEDIUM] CWE-200 hw: information disclosure on some Intel Atom processors
hw: information disclosure on some Intel Atom processors
Domain-bypass transient execution vulnerability in some Intel Atom(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
A potential domain bypass transient execution vulnerability was discovered on some Intel Atom® processors that uses a microarchitectural incidental channel. Currently this channel can reveal supervisor data in the L1 cache and the contents of recent stores. As a consequence, this issue may allow an authenticated user to potentially enable information disclosure via local access.
Debian
CVE-2020-24513: intel-microcode - Domain-bypass transient execution vulnerability in some Intel Atom(R) Processors...
vendor_debian·2020·CVSS 6.5
CVE-2020-24513 [MEDIUM] CVE-2020-24513: intel-microcode - Domain-bypass transient execution vulnerability in some Intel Atom(R) Processors...
Domain-bypass transient execution vulnerability in some Intel Atom(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20210608.1)
bullseye: resolved (fixed in 3.20210608.1)
forky: resolved (fixed in 3.20210608.1)
sid: resolved (fixed in 3.20210608.1)
trixie: resolved (fixed in 3.20210608.1)
GHSA
GHSA-7fcj-4hc5-mrph: Domain-bypass transient execution vulnerability in some Intel Atom(R) Processors may allow an authenticated user to potentially enable information dis
ghsa_unreviewed·2022-05-24
CVE-2020-24513 [MEDIUM] GHSA-7fcj-4hc5-mrph: Domain-bypass transient execution vulnerability in some Intel Atom(R) Processors may allow an authenticated user to potentially enable information dis
Domain-bypass transient execution vulnerability in some Intel Atom(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
OSV
intel-microcode vulnerabilities
osv·2021-06-09·CVSS 5.6
CVE-2020-24489 [MEDIUM] intel-microcode vulnerabilities
intel-microcode vulnerabilities
It was discovered that some Intel processors may not properly invalidate
cache entries used by Intel Virtualization Technology for Directed I/O
(VT-d). This may allow a local user to perform a privilege escalation
attack. (CVE-2020-24489)
Joseph Nuzman discovered that some Intel processors may not properly apply
EIBRS mitigations (originally developed for CVE-2017-5715) and hence may
allow unauthorized memory reads via sidechannel attacks. A local attacker
could use this to expose sensitive information, including kernel
memory. (CVE-2020-24511)
Travis Downs discovered that some Intel processors did not properly flush
cache-lines for trivial-data values. This may allow an unauthorized user to
infer the presence of these trivial-data-cache-lines via timing
OSV
CVE-2020-24513: Domain-bypass transient execution vulnerability in some Intel Atom(R) Processors may allow an authenticated user to potentially enable information dis
osv·2021-06-09·CVSS 6.5
CVE-2020-24513 [MEDIUM] CVE-2020-24513: Domain-bypass transient execution vulnerability in some Intel Atom(R) Processors may allow an authenticated user to potentially enable information dis
Domain-bypass transient execution vulnerability in some Intel Atom(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://cert-portal.siemens.com/productcert/pdf/ssa-309571.pdfhttps://lists.debian.org/debian-lts-announce/2021/07/msg00022.htmlhttps://www.debian.org/security/2021/dsa-4934https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00465.htmlhttps://cert-portal.siemens.com/productcert/pdf/ssa-309571.pdfhttps://lists.debian.org/debian-lts-announce/2021/07/msg00022.htmlhttps://www.debian.org/security/2021/dsa-4934https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00465.html
2021-06-09
Published