CVE-2020-8687
Last modified
CVE-2020-8687 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Uncontrolled search path in the installer for Intel(R) RSTe Software RAID Driver for the Intel(R) Server Board M10JNP2SB before version 4.7.0.1119 may allow an authenticated user to potentially enable escalation of privilege via local access.. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
Uncontrolled search path in the installer for Intel(R) RSTe Software RAID Driver for the Intel(R) Server Board M10JNP2SB before version 4.7.0.1119 may allow an authenticated user to potentially enable escalation of privilege via local access.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Intel | Rste Software Raid | < 4.7.0.1119 |
References
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00377.htmlPatch, Vendor Advisory
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00377.htmlPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-8687?
How severe is CVE-2020-8687?
How do I fix CVE-2020-8687?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-8681Out of bounds write in system driver for some Intel(R) Graph…7.8
- CVE-2020-8682Out of bounds read in system driver for some Intel(R) Graphi…5.5
- CVE-2020-8683Improper buffer restrictions in system driver for some Intel…5.5
- CVE-2020-8684Improper access control in firmware for Intel(R) PAC with Ar…6.7
- CVE-2020-8685Improper authentication in subsystem for Intel (R) LED Manag…4.4
- CVE-2020-8686Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2020-8688Improper input validation in the Intel(R) RAID Web Console 3…7.5
- CVE-2020-8689Improper buffer restrictions in the Intel(R) Wireless for Op…6.5
- CVE-2020-8690Protection mechanism failure in Intel(R) Ethernet 700 Series…6.7
- CVE-2020-8691A logic issue in the firmware of the Intel(R) Ethernet 700 S…6.7
- CVE-2020-8692Insufficient access control in the firmware of the Intel(R) …6.7
- CVE-2020-8693Improper buffer restrictions in the firmware of the Intel(R)…6.7
Are you affected by CVE-2020-8687?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
