CVE-2020-8744
published 2020-11-12CVE-2020-8744: Improper initialization in subsystem for Intel(R) CSME versions before12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE versions before 4.0.30…
PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.36%
27.8th percentile
Improper initialization in subsystem for Intel(R) CSME versions before12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE versions before 4.0.30 Intel(R) SPS versions before E3_05.01.04.200 may allow a privileged user to potentially enable escalation of privilege via local access.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| intel | converged_security_and_management_engine | < 12.0.70 | 12.0.70 |
| intel | converged_security_and_management_engine | >= 13.0.0 < 13.0.40 | 13.0.40 |
| intel | converged_security_and_management_engine | >= 13.30.0 < 13.30.10 | 13.30.10 |
| intel | converged_security_and_management_engine | >= 14.0.0 < 14.0.45 | 14.0.45 |
| intel | converged_security_and_management_engine | >= 14.5.0 < 14.5.25 | 14.5.25 |
| intel | server_platform_services | < e3_05.01.04.200 | e3_05.01.04.200 |
| intel | trusted_execution_engine | < 4.0.30 | 4.0.30 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC S7-1500
cisa_ics·2021-05-11·CVSS 6.7
[MEDIUM] Siemens SIMATIC S7-1500
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SIMATIC S7-1500
Last RevisedMay 11, 2021
Alert CodeICSA-21-131-15
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.8
- ATTENTION: Low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU 1518F-4
- Vulnerabilities: Improper Initialization, Improper Restriction of Operations within the Bounds of a Memory Buffer
## 2. RISK EVALUATION
Successful exploitation of these Intel product vulnerabilities could allow unauthorized privilege escalation.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following versions of SIMATIC S7-1500 CPU 1518-4, are affected by vul
GHSA
GHSA-4pp9-pcmj-qjgw: Improper initialization in subsystem for Intel(R) CSME versions before12
ghsa_unreviewed·2022-05-24
CVE-2020-8744 [HIGH] CWE-665 GHSA-4pp9-pcmj-qjgw: Improper initialization in subsystem for Intel(R) CSME versions before12
Improper initialization in subsystem for Intel(R) CSME versions before12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE versions before 4.0.30 Intel(R) SPS versions before E3_05.01.04.200 may allow a privileged user to potentially enable escalation of privilege via local access.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://cert-portal.siemens.com/productcert/pdf/ssa-501073.pdfhttps://security.netapp.com/advisory/ntap-20201113-0002/https://security.netapp.com/advisory/ntap-20201113-0004/https://security.netapp.com/advisory/ntap-20201113-0005/https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00391https://cert-portal.siemens.com/productcert/pdf/ssa-501073.pdfhttps://security.netapp.com/advisory/ntap-20201113-0002/https://security.netapp.com/advisory/ntap-20201113-0004/https://security.netapp.com/advisory/ntap-20201113-0005/https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00391
2020-11-12
Published