MEDIUM · 4.6

CVE-2020-12311

Insufficient control flow managementin firmware in some Intel(R) Client SSDs and some Intel(R) Data Center SSDs may allow an unauthenticated user to potentially enable information disclosure via physi...

Vulnerability Description

Insufficient control flow managementin firmware in some Intel(R) Client SSDs and some Intel(R) Data Center SSDs may allow an unauthenticated user to potentially enable information disclosure via physical access.

CVSS Score

4.6

MEDIUM

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
PHYSICAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
IntelSsd Pro 6000P Firmware< psf131p
IntelSsd Pro 6000P-
IntelSsd Pro 5450S Firmware< lhf005p
IntelSsd Pro 5450S-
IntelSsd E 5100S Firmware< lhf004e
IntelSsd E 5100S-
IntelSsd Pro 5400S Firmware< lbf017p
IntelSsd Pro 5400S-
IntelSsd Pro 7600P Firmware< 005p
IntelSsd Pro 7600P-
IntelSsd 760P Firmware< 005c
IntelSsd 760P-
IntelSsd E 6100P Firmware< 005e
IntelSsd E 6100P-
IntelSsd 660P Firmware< 004c
IntelSsd 660P-
IntelOptane Ssd 905P Firmware< e2010480
IntelOptane Ssd 905P-
IntelOptane Ssd 900P Firmware< e2010480
IntelOptane Ssd 900P-

References

FAQ

What is CVE-2020-12311?

CVE-2020-12311 is a vulnerability with a CVSS score of 4.6 (MEDIUM). Insufficient control flow managementin firmware in some Intel(R) Client SSDs and some Intel(R) Data Center SSDs may allow an unauthenticated user to potentially enable information disclosure via physi...

How severe is CVE-2020-12311?

CVE-2020-12311 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-12311?

Check the references section above for vendor advisories and patch information. Affected products include: Intel Ssd Pro 6000P Firmware, Intel Ssd Pro 6000P, Intel Ssd Pro 5450S Firmware, Intel Ssd Pro 5450S, Intel Ssd E 5100S Firmware.