CVE-2020-8698
published 2020-11-12CVE-2020-8698: Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local…
PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.51%
40.5th percentile
Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | intel-microcode | < intel-microcode 3.20201110.1 (bookworm) | intel-microcode 3.20201110.1 (bookworm) |
| fedoraproject | fedora | — | — |
| siemens | simatic_field_pg_m5_firmware | < 22.01.08 | 22.01.08 |
| siemens | simatic_ipc427e_firmware | < 21.01.15 | 21.01.15 |
| siemens | simatic_ipc477e_firmware | < 21.01.15 | 21.01.15 |
| siemens | simatic_ipc477e_pro_firmware | < 21.01.15 | 21.01.15 |
| siemens | simatic_ipc627e_firmware | < 25.02.08 | 25.02.08 |
| siemens | simatic_ipc647e_firmware | < 25.02.08 | 25.02.08 |
| siemens | simatic_ipc677e_firmware | < 25.02.08 | 25.02.08 |
| siemens | simatic_ipc847e_firmware | < 25.02.08 | 25.02.08 |
| siemens | simatic_itp1000_firmware | < 23.01.08 | 23.01.08 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9636-925v-53qr: Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via lo
ghsa_unreviewed·2022-05-24
CVE-2020-8698 [MEDIUM] CWE-668 GHSA-9636-925v-53qr: Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via lo
Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
OSV
intel-microcode vulnerabilities
osv·2021-05-17·CVSS 5.5
[MEDIUM] intel-microcode vulnerabilities
intel-microcode vulnerabilities
USN-4628-1 provided updated Intel Processor Microcode for various processor
types. This update provides the corresponding updates for some additional
processor types.
Original advisory details:
Moritz Lipp, Michael Schwarz, Andreas Kogler, David Oswald, Catherine
Easdon, Claudio Canella, and Daniel Gruss discovered that the Intel Running
Average Power Limit (RAPL) feature of some Intel processors allowed a side-
channel attack based on power consumption measurements. A local attacker
could possibly use this to expose sensitive information. (CVE-2020-8695)
Ezra Caltum, Joseph Nuzman, Nir Shildan and Ofir Joseff discovered that
some Intel(R) Processors did not properly remove sensitive information
before storage or transfer in some situations. A local atta
OSV
CVE-2020-8698: Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via lo
osv·2020-11-12·CVSS 5.5
CVE-2020-8698 [MEDIUM] CVE-2020-8698: Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via lo
Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
OSV
intel-microcode regression
osv·2020-11-12·CVSS 5.5
[MEDIUM] intel-microcode regression
intel-microcode regression
USN-4628-1 provided updated Intel Processor Microcode. Unfortunately,
that update prevented certain processors in the Intel Tiger Lake family
from booting successfully. This update reverts the microcode update for
the Tiger Lake processor family.
Please note that the 'dis_ucode_ldr' kernel command line option can be
added in the boot menu to disable microcode loading for system recovery.
We apologize for the inconvenience.
Original advisory details:
Moritz Lipp, Michael Schwarz, Andreas Kogler, David Oswald, Catherine
Easdon, Claudio Canella, and Daniel Gruss discovered that the Intel Running
Average Power Limit (RAPL) feature of some Intel processors allowed a side-
channel attack based on power consumption measurements. A local attacker
could possibly use
OSV
intel-microcode vulnerabilities
osv·2020-11-11·CVSS 5.5
CVE-2020-8695 [MEDIUM] intel-microcode vulnerabilities
intel-microcode vulnerabilities
Moritz Lipp, Michael Schwarz, Andreas Kogler, David Oswald, Catherine
Easdon, Claudio Canella, and Daniel Gruss discovered that the Intel Running
Average Power Limit (RAPL) feature of some Intel processors allowed a side-
channel attack based on power consumption measurements. A local attacker
could possibly use this to expose sensitive information. (CVE-2020-8695)
Ezra Caltum, Joseph Nuzman, Nir Shildan and Ofir Joseff discovered that
some Intel(R) Processors did not properly remove sensitive information
before storage or transfer in some situations. A local attacker could
possibly use this to expose sensitive information. (CVE-2020-8696)
Ezra Caltum, Joseph Nuzman, Nir Shildan and Ofir Joseff discovered that
some Intel(R) Processors did not properly iso
CISA ICS
Siemens Industrial PCs and CNC devices (Update A)
cisa_ics·2022-05-12
Siemens Industrial PCs and CNC devices (Update A)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens Industrial PCs and CNC devices (Update A)
Last RevisedDecember 15, 2022
Alert CodeICSA-22-132-05
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.8
- ATTENTION: Low attack complexity
- Vendor: Siemens
- Equipment: Industrial PCs and CNC devices
- Vulnerabilities: Improper Input Validation, Improper Authentication, Improper Isolation of Shared Resources on System-on-a-Chip, Improper Privilege Management
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the original advisory titled ICSA-22-132-05 Siemens Industrial PCs and CNC devices that was published May 12, 202
Ubuntu
Intel Microcode vulnerabilities
vendor_ubuntu·2021-05-17·CVSS 5.5
CVE-2020-8698 [MEDIUM] Intel Microcode vulnerabilities
Title: Intel Microcode vulnerabilities
Summary: Several security issues were fixed in Intel Microcode.
USN-4628-1 provided updated Intel Processor Microcode for various processor
types. This update provides the corresponding updates for some additional
processor types.
Original advisory details:
Moritz Lipp, Michael Schwarz, Andreas Kogler, David Oswald, Catherine
Easdon, Claudio Canella, and Daniel Gruss discovered that the Intel Running
Average Power Limit (RAPL) feature of some Intel processors allowed a side-
channel attack based on power consumption measurements. A local attacker
could possibly use this to expose sensitive information. (CVE-2020-8695)
Ezra Caltum, Joseph Nuzman, Nir Shildan and Ofir Joseff discovered that
some Intel(R) Processors did not properly remove sensitive
Ubuntu
Intel Microcode regression
vendor_ubuntu·2020-11-12·CVSS 5.5
[MEDIUM] Intel Microcode regression
Title: Intel Microcode regression
Summary: USN-4628-1 introduced a regression in the Intel Microcode for some processors.
USN-4628-1 provided updated Intel Processor Microcode. Unfortunately,
that update prevented certain processors in the Intel Tiger Lake family
from booting successfully. This update reverts the microcode update for
the Tiger Lake processor family.
Please note that the 'dis_ucode_ldr' kernel command line option can be
added in the boot menu to disable microcode loading for system recovery.
We apologize for the inconvenience.
Original advisory details:
Moritz Lipp, Michael Schwarz, Andreas Kogler, David Oswald, Catherine
Easdon, Claudio Canella, and Daniel Gruss discovered that the Intel Running
Average Power Limit (RAPL) feature of some Intel processors allowed a si
Ubuntu
Intel Microcode vulnerabilities
vendor_ubuntu·2020-11-11·CVSS 5.5
CVE-2020-8698 [MEDIUM] Intel Microcode vulnerabilities
Title: Intel Microcode vulnerabilities
Summary: Several security issues were fixed in Intel Microcode.
Moritz Lipp, Michael Schwarz, Andreas Kogler, David Oswald, Catherine
Easdon, Claudio Canella, and Daniel Gruss discovered that the Intel Running
Average Power Limit (RAPL) feature of some Intel processors allowed a side-
channel attack based on power consumption measurements. A local attacker
could possibly use this to expose sensitive information. (CVE-2020-8695)
Ezra Caltum, Joseph Nuzman, Nir Shildan and Ofir Joseff discovered that
some Intel(R) Processors did not properly remove sensitive information
before storage or transfer in some situations. A local attacker could
possibly use this to expose sensitive information. (CVE-2020-8696)
Ezra Caltum, Joseph Nuzman, Nir Shildan and O
Red Hat
hw: Fast forward store predictor
vendor_redhat·2020-11-10·CVSS 5.5
CVE-2020-8698 [MEDIUM] CWE-212 hw: Fast forward store predictor
hw: Fast forward store predictor
Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
A flaw was found in the CPU microarchitecture where a local attacker is able to abuse a timing issue which may allow them to infer internal architectural state from previous executions on the CPU.
Package: microcode_ctl (Red Hat Enterprise Linux 5) - Out of support scope
Debian
CVE-2020-8698: intel-microcode - Improper isolation of shared resources in some Intel(R) Processors may allow an ...
vendor_debian·2020·CVSS 5.5
CVE-2020-8698 [MEDIUM] CVE-2020-8698: intel-microcode - Improper isolation of shared resources in some Intel(R) Processors may allow an ...
Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20201110.1)
bullseye: resolved (fixed in 3.20201110.1)
forky: resolved (fixed in 3.20201110.1)
sid: resolved (fixed in 3.20201110.1)
trixie: resolved (fixed in 3.20201110.1)
No detection rules found.
No public exploits indexed.
CWE
Exposure of Sensitive Information caused by Incorrect Data Forwarding during Transient Execution
mitre_cwe
CWE-1422 Exposure of Sensitive Information caused by Incorrect Data Forwarding during Transient Execution
CWE-1422: Exposure of Sensitive Information caused by Incorrect Data Forwarding during Transient Execution
A processor event or prediction may allow incorrect or stale data to
be forwarded to transient operations, potentially exposing data over a
covert channel.
Software may use a variety of techniques to preserve the
confidentiality of private data that is accessible within the current
processor context. For example, the memory safety and type safety
properties of some high-level programming languages help to prevent
software written in those languages from exposing private data. As a
second example, software sandboxes may co-locate multiple users'
software within a single process. The processor's Instruction Set
Architecture (ISA) may permit one user's software to access another
user's
CWE
Improper Isolation of Shared Resources on System-on-a-Chip (SoC)
mitre_cwe
CWE-1189 Improper Isolation of Shared Resources on System-on-a-Chip (SoC)
CWE-1189: Improper Isolation of Shared Resources on System-on-a-Chip (SoC)
The System-On-a-Chip (SoC) does not properly isolate shared resources between trusted and untrusted agents.
A System-On-a-Chip (SoC) has a lot of functionality, but it may have a limited number of pins or pads. A pin can only perform one function at a time. However, it can be configured to perform multiple different functions. This technique is called pin multiplexing. Similarly, several resources on the chip may be shared to multiplex and support different features or functions. When such resources are shared between trusted and untrusted agents, untrusted agents may be able to access the assets intended to be accessed only by the trusted agents.
Modes of Introduction:
Phase: Architecture and Design
Phase: Imple
https://cert-portal.siemens.com/productcert/pdf/ssa-678983.pdfhttps://lists.debian.org/debian-lts-announce/2021/02/msg00007.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MAAGIK5CXKBPGY3R4UR5VO56M7MKLZ43/https://security.netapp.com/advisory/ntap-20201113-0006/https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00381https://cert-portal.siemens.com/productcert/pdf/ssa-678983.pdfhttps://lists.debian.org/debian-lts-announce/2021/02/msg00007.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MAAGIK5CXKBPGY3R4UR5VO56M7MKLZ43/https://security.netapp.com/advisory/ntap-20201113-0006/https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00381
2020-11-12
Published