CVE-2020-8745

MEDIUMCVSS 6.8/10EPSS 0.38%

Last modified

CVE-2020-8745 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. Insufficient control flow management in subsystem for Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25 , Intel(R) TXE versions before 3.1.80 and 4.0.30 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.. EPSS estimates a 0.38% chance of exploitation in the next 30 days.

Description

Insufficient control flow management in subsystem for Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25 , Intel(R) TXE versions before 3.1.80 and 4.0.30 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

Metrics

CVSS 3.1
6.8/10

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.38%

29.6th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
IntelConverged Security And Manageability Engine< 11.8.80
IntelConverged Security And Manageability Engine>= 11.12.0, < 11.12.80
IntelConverged Security And Manageability Engine>= 11.22.0, < 11.22.80
IntelConverged Security And Manageability Engine>= 12.0, < 12.0.70
IntelConverged Security And Manageability Engine>= 14.0, < 14.0.45
IntelConverged Security And Manageability Engine>= 14.5.0, < 14.5.25
IntelTrusted Execution Technology< 3.1.80
IntelTrusted Execution Technology>= 4.0, < 4.0.30
SiemensSimatic Drive Controller Firmware< 05.00.01.00
SiemensSimatic Et200sp 1515sp Pc2 Firmware< 0209.0105
SiemensSimatic Field Pg M5 Firmware< 22.01.08
SiemensSimatic Field Pg M6 FirmwareAll versions
SiemensSimatic Ipc127e Firmware< 27.01.05
SiemensSimatic Ipc427e Firmware< 27.01.05
SiemensSimatic Ipc477e Firmware< 21.01.15
SiemensSimatic Ipc527g Firmware< 1.4.0
SiemensSimatic Ipc547g Firmware< r1.30.0
SiemensSimatic Ipc627e Firmware< 25.02.08
SiemensSimatic Ipc647e Firmware< 25.02.08
SiemensSimatic Ipc667e Firmware< 25.02.08
SiemensSimatic Ipc847e Firmware< 25.02.08
SiemensSimatic Itp1000 Firmware< 23.01.08
SiemensSinumerik 828d Hw Pu.4 Firmware< 08.00.00.00
SiemensSinumerik Mc Mcu 1720 Firmware< 05.00.00.00
SiemensSinumerik One FirmwareAll versions
SiemensSinumerik 840d Sl Ht 10 FirmwareAll versions
SiemensSinumerik One Ncu 1740 Firmware< 04.00.00.00
SiemensSinumerik One Ppu 1740 Firmware< 06.00.00.00

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2020-8745?
Insufficient control flow management in subsystem for Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25 , Intel(R) TXE versions before 3.1.80 and 4.0.30 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
How severe is CVE-2020-8745?
CVE-2020-8745 has a CVSS score of 6.8/10 (MEDIUM severity). The EPSS model estimates a 0.38% probability of exploitation in the next 30 days.
How do I fix CVE-2020-8745?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-8745?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST