CVE-2020-8761

Severity CVSS v4.0:
Pending analysis
Type:
CWE-326 Inadequate Encryption Strength
Publication date:
12/11/2020
Last modified:
30/11/2020

Description

Inadequate encryption strength in subsystem for Intel(R) CSME versions before 13.0.40 and 13.30.10 may allow an unauthenticated user to potentially enable information disclosure via physical access.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:intel:converged_security_and_manageability_engine:*:*:*:*:*:*:*:* 13.0.40 (excluding)
cpe:2.3:a:intel:converged_security_and_manageability_engine:*:*:*:*:*:*:*:* 13.30.0 (including) 13.30.10 (excluding)