CVE-2020-8742

Severity
6.7MEDIUM
EPSS
0.1%
top 80.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 13
Latest updateMay 24

Description

Improper input validation in the firmware for Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.8 | Impact: 5.9

Affected Packages74 packages

NVDintel/cd1c32gk_firmware< gkaplcpx.86a
NVDintel/cd1c64gk_firmware< gkaplcpx.86a
NVDintel/cd1p64gk_firmware< gkaplcpx.86a
NVDintel/nuc5cpyh_firmware< pybswcel.86a
NVDintel/nuc5pgyh_firmware< pybswcel.86a

Patches

🔴Vulnerability Details

2
GHSA
GHSA-2qmh-c7cm-qw9m: Improper input validation in the firmware for Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access2022-05-24
CVEList
CVE-2020-8742: Improper input validation in the firmware for Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access2020-08-13
CVE-2020-8742 (MEDIUM CVSS 6.7) | Improper input validation in the fi | cvebase.io