CVE-2020-8745

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
12/11/2020
Last modified:
28/03/2025

Description

Insufficient control flow management in subsystem for Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25 , Intel(R) TXE versions before 3.1.80 and 4.0.30 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:intel:converged_security_and_manageability_engine:*:*:*:*:*:*:*:* 11.8.80 (excluding)
cpe:2.3:a:intel:converged_security_and_manageability_engine:*:*:*:*:*:*:*:* 11.12.0 (including) 11.12.80 (excluding)
cpe:2.3:a:intel:converged_security_and_manageability_engine:*:*:*:*:*:*:*:* 11.22.0 (including) 11.22.80 (excluding)
cpe:2.3:a:intel:converged_security_and_manageability_engine:*:*:*:*:*:*:*:* 12.0 (including) 12.0.70 (excluding)
cpe:2.3:a:intel:converged_security_and_manageability_engine:*:*:*:*:*:*:*:* 14.0 (including) 14.0.45 (excluding)
cpe:2.3:a:intel:converged_security_and_manageability_engine:*:*:*:*:*:*:*:* 14.5.0 (including) 14.5.25 (excluding)
cpe:2.3:a:intel:trusted_execution_technology:*:*:*:*:*:*:*:* 3.1.80 (excluding)
cpe:2.3:a:intel:trusted_execution_technology:*:*:*:*:*:*:*:* 4.0 (including) 4.0.30 (excluding)
cpe:2.3:o:siemens:simatic_drive_controller_firmware:*:*:*:*:*:*:*:* 05.00.01.00 (excluding)
cpe:2.3:h:siemens:simatic_drive_controller:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_et200sp_1515sp_pc2_firmware:*:*:*:*:*:*:*:* 0209.0105 (excluding)
cpe:2.3:h:siemens:simatic_et200sp_1515sp_pc2:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_field_pg_m5_firmware:*:*:*:*:*:*:*:* 22.01.08 (excluding)
cpe:2.3:h:siemens:simatic_field_pg_m5:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_field_pg_m6_firmware:-:*:*:*:*:*:*:*