CVE-2020-8745
published 2020-11-12CVE-2020-8745: Insufficient control flow management in subsystem for Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and…
PriorityP428medium6.8CVSS 3.1
AVPACLPRNUINSUCHIHAH
EPSS
0.38%
29.9th percentile
Insufficient control flow management in subsystem for Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25 , Intel(R) TXE versions before 3.1.80 and 4.0.30 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| intel | converged_security_and_manageability_engine | < 11.8.80 | 11.8.80 |
| intel | converged_security_and_manageability_engine | >= 11.12.0 < 11.12.80 | 11.12.80 |
| intel | converged_security_and_manageability_engine | >= 11.22.0 < 11.22.80 | 11.22.80 |
| intel | converged_security_and_manageability_engine | >= 12.0 < 12.0.70 | 12.0.70 |
| intel | converged_security_and_manageability_engine | >= 14.0 < 14.0.45 | 14.0.45 |
| intel | converged_security_and_manageability_engine | >= 14.5.0 < 14.5.25 | 14.5.25 |
| intel | trusted_execution_technology | < 3.1.80 | 3.1.80 |
| intel | trusted_execution_technology | >= 4.0 < 4.0.30 | 4.0.30 |
| siemens | simatic_drive_controller_firmware | < 05.00.01.00 | 05.00.01.00 |
| siemens | simatic_et200sp_1515sp_pc2_firmware | < 0209.0105 | 0209.0105 |
| siemens | simatic_field_pg_m5_firmware | < 22.01.08 | 22.01.08 |
| siemens | simatic_ipc127e_firmware | < 27.01.05 | 27.01.05 |
| siemens | simatic_ipc427e_firmware | < 27.01.05 | 27.01.05 |
| siemens | simatic_ipc477e_firmware | < 21.01.15 | 21.01.15 |
| siemens | simatic_ipc527g_firmware | < 1.4.0 | 1.4.0 |
| siemens | simatic_ipc547g_firmware | < r1.30.0 | r1.30.0 |
| siemens | simatic_ipc627e_firmware | < 25.02.08 | 25.02.08 |
| siemens | simatic_ipc647e_firmware | < 25.02.08 | 25.02.08 |
| siemens | simatic_ipc667e_firmware | < 25.02.08 | 25.02.08 |
| siemens | simatic_ipc847e_firmware | < 25.02.08 | 25.02.08 |
| siemens | simatic_itp1000_firmware | < 23.01.08 | 23.01.08 |
| siemens | sinumerik_828d_hw_pu.4_firmware | < 08.00.00.00 | 08.00.00.00 |
| siemens | sinumerik_mc_mcu_1720_firmware | < 05.00.00.00 | 05.00.00.00 |
| siemens | sinumerik_one_ncu_1740_firmware | < 04.00.00.00 | 04.00.00.00 |
| siemens | sinumerik_one_ppu_1740_firmware | < 06.00.00.00 | 06.00.00.00 |
CVSS provenance
nvdv3.16.8MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens Industrial PCs and CNC devices (Update A)
cisa_ics·2022-05-12
Siemens Industrial PCs and CNC devices (Update A)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens Industrial PCs and CNC devices (Update A)
Last RevisedDecember 15, 2022
Alert CodeICSA-22-132-05
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.8
- ATTENTION: Low attack complexity
- Vendor: Siemens
- Equipment: Industrial PCs and CNC devices
- Vulnerabilities: Improper Input Validation, Improper Authentication, Improper Isolation of Shared Resources on System-on-a-Chip, Improper Privilege Management
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the original advisory titled ICSA-22-132-05 Siemens Industrial PCs and CNC devices that was published May 12, 202
GHSA
GHSA-wc8w-gx27-xp92: Insufficient control flow management in subsystem for Intel(R) CSME versions before 11
ghsa_unreviewed·2022-05-24
CVE-2020-8745 [MEDIUM] CWE-269 GHSA-wc8w-gx27-xp92: Insufficient control flow management in subsystem for Intel(R) CSME versions before 11
Insufficient control flow management in subsystem for Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25 , Intel(R) TXE versions before 3.1.80 and 4.0.30 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://cert-portal.siemens.com/productcert/pdf/ssa-678983.pdfhttps://security.netapp.com/advisory/ntap-20201113-0002/https://security.netapp.com/advisory/ntap-20201113-0005/https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00391https://cert-portal.siemens.com/productcert/pdf/ssa-678983.pdfhttps://security.netapp.com/advisory/ntap-20201113-0002/https://security.netapp.com/advisory/ntap-20201113-0005/https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00391
2020-11-12
Published