MEDIUM · 6.8

CVE-2020-8745

Insufficient control flow management in subsystem for Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25 , Intel(R) TXE versions before 3.1.80 a...

Vulnerability Description

Insufficient control flow management in subsystem for Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25 , Intel(R) TXE versions before 3.1.80 and 4.0.30 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

CVSS Score

6.8

MEDIUM

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
PHYSICAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
IntelConverged Security And Manageability Engine< 11.8.80
IntelTrusted Execution Technology< 3.1.80
SiemensSimatic Drive Controller Firmware< 05.00.01.00
SiemensSimatic Drive Controller-
SiemensSimatic Et200Sp 1515Sp Pc2 Firmware< 0209.0105
SiemensSimatic Et200Sp 1515Sp Pc2-
SiemensSimatic Field Pg M5 Firmware< 22.01.08
SiemensSimatic Field Pg M5-
SiemensSimatic Field Pg M6 Firmware-
SiemensSimatic Field Pg M6-
SiemensSimatic Ipc127E Firmware< 27.01.05
SiemensSimatic Ipc127E-
SiemensSimatic Ipc427E Firmware< 27.01.05
SiemensSimatic Ipc427E-
SiemensSimatic Ipc477E Firmware< 21.01.15
SiemensSimatic Ipc477E-
SiemensSimatic Ipc477E Pro-
SiemensSimatic Ipc527G Firmware< 1.4.0
SiemensSimatic Ipc527G-
SiemensSimatic Ipc547G Firmware< r1.30.0

References

FAQ

What is CVE-2020-8745?

CVE-2020-8745 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Insufficient control flow management in subsystem for Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25 , Intel(R) TXE versions before 3.1.80 a...

How severe is CVE-2020-8745?

CVE-2020-8745 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-8745?

Check the references section above for vendor advisories and patch information. Affected products include: Intel Converged Security And Manageability Engine, Intel Trusted Execution Technology, Siemens Simatic Drive Controller Firmware, Siemens Simatic Drive Controller, Siemens Simatic Et200Sp 1515Sp Pc2 Firmware.