CVE-2020-0526

MEDIUMCVSS 6.7/10EPSS 0.34%

Last modified

CVE-2020-0526 is a medium-severity vulnerability rated 6.7/10 on the CVSS scale. Improper input validation in firmware for Intel(R) NUC may allow a privileged user to potentially enable escalation of privilege via local access. The list of affected products is provided in intel-sa-00343: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00343.html. EPSS estimates a 0.34% chance of exploitation in the next 30 days.

Description

Improper input validation in firmware for Intel(R) NUC may allow a privileged user to potentially enable escalation of privilege via local access. The list of affected products is provided in intel-sa-00343: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00343.html

Metrics

CVSS 3.1
6.7/10

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.34%

25.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
IntelNuc Kit Nuc8i7bek Firmwarebecfl357.86a.0077
IntelNuc 8 Enthusiast Pc Nuc8i7bekqa Firmwarebecfl357.86a.0077
IntelNuc Kit Nuc8i7hnk Firmwarehnkbli70.86a.0059
IntelNuc 8 Business Pc Nuc8i7hnkqc Firmwarehnkbli70.86a.0059
IntelNuc 8 Mainstream-G Kit Nuc8i7inh Firmwareinwhl357.0036
IntelNuc 8 Mainstream-G Kit Nuc8i5inh Firmwareinwhl357.0036
IntelNuc 8 Mainstream-G Mini Pc Nuc8i7inh Firmwareinwhl357.0036
IntelNuc 8 Rugged Kit Nuc8cchkr Firmwarechaplcel.0047
IntelNuc Board Nuc8cchb Firmwarechaplcel.0047
IntelNuc 8 Home Pc Nuc8i3cysm Firmwarecycnli35.86a.0044
IntelNuc Kit Nuc7i7dnke Firmwarednkbli7v.86a.0067
IntelNuc Kit Nuc7i7dnhe Firmwarednkbli7v.86a.0067
IntelNuc Kit Nuc7i5dnke Firmwarednkbli5v.86a.0067
IntelNuc Kit Nuc7i5dnhe Firmwarednkbli5v.86a.0067
IntelNuc Kit Nuc7i3dnke Firmwarednkbli30.86a.0067
IntelNuc Kit Nuc7i3dnhe Firmwarednkbli30.86a.0067
IntelNuc Board Nuc7i7dnbe Firmwarednkbli7v.86a.0067
IntelNuc Board Nuc7i5dnbe Firmwarednkbli5v.86a.0067
IntelNuc Board Nuc7i3dnbe Firmwarednkbli30.86a.0067
IntelCompute Stick Stk2m3w64cc Firmwareccsklm30.86a.0062
IntelCompute Stick Stk2m364cc Firmwareccsklm30.86a.0062
IntelCompute Stick Stk1a32sc Firmwaresc0045
IntelCompute Stick Stk1aw32sc Firmwaresc0045
IntelNuc Kit Nuc6i7kyk Firmwarekyskli70.86a.0066
IntelNuc 7 Essential Pc Nuc7cjysal Firmwarejyglkcpx.86a.0053
IntelNuc Kit Nuc7cjyh Firmwarejyglkcpx.86a.0053
IntelNuc Kit Nuc7pjyh Firmwarejyglkcpx.86a.0053
IntelNuc Kit Nuc7i7bnh Firmwarebnkbl357.86a.0081
IntelNuc Kit Nuc7i5bnk Firmwarebnkbl357.86a.0081
IntelNuc Kit Nuc7i3bnh Firmwarebnkbl357.86a.0081
IntelNuc Kit Nuc7i5bnh Firmwarebnkbl357.86a.0081
IntelNuc Kit Nuc7i3bnk Firmwarebnkbl357.86a.0081
IntelNuc Kit Nuc7i7bnhx1 Firmwarebnkbl357.86a.0081
IntelNuc Kit Nuc7i5bnhx1 Firmwarebnkbl357.86a.0081
IntelNuc Kit Nuc7i3bnhx1 Firmwarebnkbl357.86a.0081
IntelNuc 7 Enthusiast Pc Nuc7i7bnhxg Firmwarebnkbl357.86a.0081
IntelNuc 7 Home A Mini Pc Nuc7i5bnhxf Firmwarebnkbl357.86a.0081
IntelNuc 7 Home A Mini Pc Nuc7i3bnhxf Firmwarebnkbl357.86a.0081
IntelNuc 7 Home A Mini Pc Nuc7i5bnkp Firmwarebnkbl357.86a.0081
IntelNuc Kit Nuc6cays Firmwareayaplcel.86a.0066
IntelNuc Kit Nuc6cayh Firmwareayaplcel.86a.0066
IntelNuc Kit De3815tykhe Firmwaretybyt20h.86a.0024
IntelNuc Board De3815tybe Firmwaretybyt20h.86a.0024
IntelNuc Kit Nuc6i3syh Firmwaresyskli35.86a.0072
IntelNuc Kit Nuc6i5syh Firmwaresyskli35.86a.0072
IntelNuc Kit Nuc6i3syk Firmwaresyskli35.86a.0072
IntelNuc Kit Nuc6i5syk Firmwaresyskli35.86a.0072
IntelNuc Kit Nuc5pgyh Firmwarepybswcel.86a.0078
IntelNuc Kit Nuc5ppyh Firmwarepybswcel.86a.0078
IntelNuc Kit Nuc5cpyh Firmwarepybswcel.86a.0078

Showing 50 of 70 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-0526?
Improper input validation in firmware for Intel(R) NUC may allow a privileged user to potentially enable escalation of privilege via local access. The list of affected products is provided in intel-sa-00343: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00343.html
How severe is CVE-2020-0526?
CVE-2020-0526 has a CVSS score of 6.7/10 (MEDIUM severity). The EPSS model estimates a 0.34% probability of exploitation in the next 30 days.
How do I fix CVE-2020-0526?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-0526?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST