CVE-2020-8755

CWE-362Race Condition3 documents3 sources
Severity
6.4MEDIUM
EPSS
0.1%
top 79.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 12
Latest updateMay 24

Description

Race condition in subsystem for Intel(R) CSME versions before 12.0.70 and 14.0.45, Intel(R) SPS versions before E5_04.01.04.400 and E3_05.01.04.200 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

CVSS vector

CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 0.5 | Impact: 5.9

Affected Packages2 packages

NVDintel/server_platform_services< e5_04.01.04.400+1

🔴Vulnerability Details

2
GHSA
GHSA-cqmw-3h5w-7xq6: Race condition in subsystem for Intel(R) CSME versions before 122022-05-24
CVEList
CVE-2020-8755: Race condition in subsystem for Intel(R) CSME versions before 122020-11-12
CVE-2020-8755 (MEDIUM CVSS 6.4) | Race condition in subsystem for Int | cvebase.io