CVE-2020-0549
MEDIUMCVSS 5.5/10EPSS 0.59%
Last modified
CVE-2020-0549 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. Cleanup errors in some data cache evictions for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.. EPSS estimates a 0.59% chance of exploitation in the next 30 days.
Description
Cleanup errors in some data cache evictions for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Intel | Core I7-8700b Firmware | All versions |
| Intel | Core I7-8569u Firmware | All versions |
| Intel | Core I7 8650u Firmware | All versions |
| Intel | Core I7 8565u Firmware | All versions |
| Intel | Core I7 8560u Firmware | All versions |
| Intel | Core I7 8559u Firmware | All versions |
| Intel | Core I7 8550u Firmware | All versions |
| Intel | Core I7 8500y Firmware | All versions |
| Intel | Core I7 10510y Firmware | All versions |
| Intel | Core I5 10310y Firmware | All versions |
| Intel | Core I5 10210y Firmware | All versions |
| Intel | Core I5 10110y Firmware | All versions |
| Intel | Xeon 8253 Firmware | All versions |
| Intel | Xeon 8256 Firmware | All versions |
| Intel | Xeon 8260 Firmware | All versions |
| Intel | Xeon 8260l Firmware | All versions |
| Intel | Xeon 8260m Firmware | All versions |
| Intel | Xeon 8260y Firmware | All versions |
| Intel | Xeon 8268 Firmware | All versions |
| Intel | Xeon 8270 Firmware | All versions |
| Intel | Xeon 8276 Firmware | All versions |
| Intel | Xeon 8276l Firmware | All versions |
| Intel | Xeon 8276m Firmware | All versions |
| Intel | Xeon 8280 Firmware | All versions |
| Intel | Xeon 8280l Firmware | All versions |
| Intel | Xeon 8280m Firmware | All versions |
| Intel | Xeon 9220 Firmware | All versions |
| Intel | Xeon 9221 Firmware | All versions |
| Intel | Xeon 9222 Firmware | All versions |
| Intel | Xeon 9242 Firmware | All versions |
| Intel | Xeon 9282 Firmware | All versions |
| Intel | Xeon 5215 Firmware | All versions |
| Intel | Xeon 5215l Firmware | All versions |
| Intel | Xeon 5215m Firmware | All versions |
| Intel | Xeon 5215r Firmware | All versions |
| Intel | Xeon 5217 Firmware | All versions |
| Intel | Xeon 5218 Firmware | All versions |
| Intel | Xeon 5218b Firmware | All versions |
| Intel | Xeon 5218n Firmware | All versions |
| Intel | Xeon 5218t Firmware | All versions |
| Intel | Xeon 5220 Firmware | All versions |
| Intel | Xeon 5220r Firmware | All versions |
| Intel | Xeon 5220s Firmware | All versions |
| Intel | Xeon 5220t Firmware | All versions |
| Intel | Xeon 5222 Firmware | All versions |
| Intel | Xeon 6222v Firmware | All versions |
| Intel | Xeon 6226 Firmware | All versions |
| Intel | Xeon 6230 Firmware | All versions |
| Intel | Xeon 6230n Firmware | All versions |
| Intel | Xeon 6230t Firmware | All versions |
Showing 50 of 438 affected configurations. See NVD for the full list.
References
- http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00016.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/06/msg00019.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20200210-0004/Third Party Advisory
- https://usn.ubuntu.com/4385-1/Third Party Advisory
- https://www.debian.org/security/2020/dsa-4701Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00016.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/06/msg00019.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20200210-0004/Third Party Advisory
- https://usn.ubuntu.com/4385-1/Third Party Advisory
- https://www.debian.org/security/2020/dsa-4701Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-0549?
Cleanup errors in some data cache evictions for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
How severe is CVE-2020-0549?
CVE-2020-0549 has a CVSS score of 5.5/10 (MEDIUM severity). The EPSS model estimates a 0.59% probability of exploitation in the next 30 days.
How do I fix CVE-2020-0549?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
Are you affected by CVE-2020-0549?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
