Vulnerability Description
Improper buffer restrictions in firmware for Intel(R) NUC may allow an authenticated user to potentially enable escalation of privilege via local access. The list of affected products is provided in intel-sa-00343: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00343.html
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Intel | Nuc Kit Nuc8I7Bek Firmware | becfl357.86a.0077 |
| Intel | Nuc Kit Nuc8I7Bek | - |
| Intel | Nuc 8 Enthusiast Pc Nuc8I7Bekqa Firmware | becfl357.86a.0077 |
| Intel | Nuc 8 Enthusiast Pc Nuc8I7Bekqa | - |
| Intel | Nuc Kit Nuc8I7Hnk Firmware | hnkbli70.86a.0059 |
| Intel | Nuc Kit Nuc8I7Hnk | - |
| Intel | Nuc 8 Business Pc Nuc8I7Hnkqc Firmware | hnkbli70.86a.0059 |
| Intel | Nuc 8 Business Pc Nuc8I7Hnkqc | - |
| Intel | Nuc 8 Mainstream-G Kit Nuc8I7Inh Firmware | inwhl357.0036 |
| Intel | Nuc 8 Mainstream-G Kit Nuc8I7Inh | - |
| Intel | Nuc 8 Mainstream-G Kit Nuc8I5Inh Firmware | inwhl357.0036 |
| Intel | Nuc 8 Mainstream-G Kit Nuc8I5Inh | - |
| Intel | Nuc 8 Mainstream-G Mini Pc Nuc8I7Inh Firmware | inwhl357.0036 |
| Intel | Nuc 8 Mainstream-G Mini Pc Nuc8I7Inh | - |
| Intel | Nuc 8 Rugged Kit Nuc8Cchkr Firmware | chaplcel.0047 |
| Intel | Nuc 8 Rugged Kit Nuc8Cchkr | - |
| Intel | Nuc Board Nuc8Cchb Firmware | chaplcel.0047 |
| Intel | Nuc Board Nuc8Cchb | - |
| Intel | Nuc 8 Home Pc Nuc8I3Cysm Firmware | cycnli35.86a.0044 |
| Intel | Nuc 8 Home Pc Nuc8I3Cysm | - |
Related Weaknesses (CWE)
References
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00343.Vendor Advisory
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00343.Vendor Advisory
FAQ
What is CVE-2020-0530?
CVE-2020-0530 is a vulnerability with a CVSS score of 7.8 (HIGH). Improper buffer restrictions in firmware for Intel(R) NUC may allow an authenticated user to potentially enable escalation of privilege via local access. The list of affected products is provided in i...
How severe is CVE-2020-0530?
CVE-2020-0530 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-0530?
Check the references section above for vendor advisories and patch information. Affected products include: Intel Nuc Kit Nuc8I7Bek Firmware, Intel Nuc Kit Nuc8I7Bek, Intel Nuc 8 Enthusiast Pc Nuc8I7Bekqa Firmware, Intel Nuc 8 Enthusiast Pc Nuc8I7Bekqa, Intel Nuc Kit Nuc8I7Hnk Firmware.