MEDIUM · 5.5

CVE-2020-8694

Insufficient access control in the Linux kernel driver for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

Vulnerability Description

Insufficient access control in the Linux kernel driver for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVSS Score

5.5

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
IntelCore I7-8510Y Firmware-
IntelCore I7-8510Y-
IntelCore I7-8500Y Firmware-
IntelCore I7-8500Y-
IntelCore I5-8310Y Firmware-
IntelCore I5-8310Y-
IntelCore I5-8210Y Firmware-
IntelCore I5-8210Y-
IntelCore I5-8200Y Firmware-
IntelCore I5-8200Y-
IntelCore M3-8100Y Firmware-
IntelCore M3-8100Y-
IntelCore I7-7500U Firmware-
IntelCore I7-7500U-
IntelCore I7-7510U Firmware-
IntelCore I7-7510U-
IntelCore I7-7600U Firmware-
IntelCore I7-7600U-
IntelCore I5-7200U Firmware-
IntelCore I5-7200U-

References

FAQ

What is CVE-2020-8694?

CVE-2020-8694 is a vulnerability with a CVSS score of 5.5 (MEDIUM). Insufficient access control in the Linux kernel driver for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

How severe is CVE-2020-8694?

CVE-2020-8694 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-8694?

Check the references section above for vendor advisories and patch information. Affected products include: Intel Core I7-8510Y Firmware, Intel Core I7-8510Y, Intel Core I7-8500Y Firmware, Intel Core I7-8500Y, Intel Core I5-8310Y Firmware.