CVE-2020-5955
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
03/11/2021
Last modified:
12/07/2022
Description
An issue was discovered in Int15MicrocodeSmm in Insyde InsydeH2O before 2021-10-14 on Intel client chipsets. A caller may be able to escalate privileges.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:insyde:insydeh2o_uefi_bios:*:*:*:*:*:*:*:* | 05.32.30.0001 (excluding) | |
| cpe:2.3:h:intel:ice_lake:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:insyde:insydeh2o_uefi_bios:*:*:*:*:*:*:*:* | 05.41.35.0001 (excluding) | |
| cpe:2.3:h:intel:tiger_lake:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:insyde:insydeh2o_uefi_bios:*:*:*:*:*:*:*:* | 05.42.11.0026 (excluding) | |
| cpe:2.3:h:intel:whitley-sp:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:insyde:insydeh2o_uefi_bios:*:*:*:*:*:*:*:* | 05.04.21.0068 (excluding) | |
| cpe:2.3:h:intel:grantley-ep:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:insyde:insydeh2o_uefi_bios:*:*:*:*:*:*:*:* | 05.42.09.0003 (excluding) | |
| cpe:2.3:h:intel:elkhart_lake:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:insyde:insydeh2o_uefi_bios:*:*:*:*:*:*:*:* | 05.21.51.0040 (excluding) | |
| cpe:2.3:h:intel:purley-ep_refresh_neon_city:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:insyde:insydeh2o_uefi_bios:*:*:*:*:*:*:*:* | 05.34.09.0030 (excluding) | |
| cpe:2.3:h:intel:comet_lake_rvp:-:*:*:*:embedded:*:*:* | ||
| cpe:2.3:o:insyde:insydeh2o_uefi_bios:*:*:*:*:*:*:*:* | 05.34.09.0030 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



