CVE-2020-8742

MEDIUMCVSS 6.7/10EPSS 0.32%

Last modified

CVE-2020-8742 is a medium-severity vulnerability rated 6.7/10 on the CVSS scale. Improper input validation in the firmware for Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access.. EPSS estimates a 0.32% chance of exploitation in the next 30 days.

Description

Improper input validation in the firmware for Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access.

Metrics

CVSS 3.1
6.7/10

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.32%

23.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
IntelNuc8i7behga Firmware< becfl357.86a
IntelNuc8i7bekqa Firmware< becfl357.86a
IntelNuc8i3behfa Firmware< becfl357.86a
IntelNuc8i5behfa Firmware< becfl357.86a
IntelNuc8i5bekpa Firmware< becfl357.86a
IntelNuc8i3beh Firmware< becfl357.86a
IntelNuc8i3behs Firmware< becfl357.86a
IntelNuc8i3bek Firmware< becfl357.86a
IntelNuc8i5beh Firmware< becfl357.86a
IntelNuc8i5behs Firmware< becfl357.86a
IntelNuc8i5bek Firmware< becfl357.86a
IntelNuc8i7beh Firmware< becfl357.86a
IntelNuc8i7bek Firmware< becfl357.86a
IntelCd1c32gk Firmware< gkaplcpx.86a
IntelCd1c64gk Firmware< gkaplcpx.86a
IntelCd1p64gk Firmware< gkaplcpx.86a
IntelNuc8i7hnkqc Firmware< hnkbli70.86a
IntelNuc8i7hvkva Firmware< hnkbli70.86a
IntelNuc8i7hvkvaw Firmware< hnkbli70.86a
IntelNuc8i7hnk Firmware< hnkbli70.86a
IntelNuc8i7hvk Firmware< hnkbli70.86a
IntelNuc7i7dnbe Firmware< dnkbli7v.86a
IntelNuc7i7dnhe Firmware< dnkbli7v.86a
IntelNuc7i7dnke Firmware< dnkbli7v.86a
IntelNuc7i5dnkpc Firmware< dnkbli5v.86a
IntelNuc7i5dnbe Firmware< dnkbli5v.86a
IntelNuc7i5dnhe Firmware< dnkbli5v.86a
IntelNuc7i5dnke Firmware< dnkbli5v.86a
IntelNuc7i3dnhnc Firmware< dnkbli30.86a
IntelNuc7i3dnktc Firmware< dnkbli30.86a
IntelNuc7i3dnbe Firmware< dnkbli30.86a
IntelNuc7i3dnhe Firmware< dnkbli30.86a
IntelNuc7i3dnke Firmware< dnkbli30.86a
IntelStk2mv64cc Firmware< ccsklm5v.86a
IntelNuc6i7kyk Firmware< kyskli70.86a
IntelNuc7cjysal Firmware< jyglkcpx.86a
IntelNuc7cjyh Firmware< jyglkcpx.86a
IntelNuc7pjyh Firmware< jyglkcpx.86a
IntelNuc7i7bnhxg Firmware< bnkbl357.86a
IntelNuc7i7bnkq Firmware< bnkbl357.86a
IntelNuc7i3bnhxf Firmware< bnkbl357.86a
IntelNuc7i5bnhxf Firmware< bnkbl357.86a
IntelNuc7i5bnkp Firmware< bnkbl357.86a
IntelNuc7i3bnb Firmware< bnkbl357.86a
IntelNuc7i5bnb Firmware< bnkbl357.86a
IntelNuc7i7bnb Firmware< bnkbl357.86a
IntelNuc7i3bnh Firmware< bnkbl357.86a
IntelNuc7i3bnhx1 Firmware< bnkbl357.86a
IntelNuc7i3bnk Firmware< bnkbl357.86a
IntelNuc7i5bnh Firmware< bnkbl357.86a

Showing 50 of 75 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-8742?
Improper input validation in the firmware for Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access.
How severe is CVE-2020-8742?
CVE-2020-8742 has a CVSS score of 6.7/10 (MEDIUM severity). The EPSS model estimates a 0.32% probability of exploitation in the next 30 days.
How do I fix CVE-2020-8742?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-8742?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST