VulnerabilityModified
CVE-2020-0549
Cleanup errors in some data cache evictions for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
MEDIUM 5.5EPSS 0.56%
Does this matter?
Lower severity and a low EPSS score (0.56%). Track it; it rarely justifies an emergency change on its own.
Description
Cleanup errors in some data cache evictions for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.56% probability · 45th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-404
- Affected
- intel/core i7-8700b firmware · intel/core i7-8569u firmware · intel/core i7 8650u firmware · intel/core i7 8565u firmware · intel/core i7 8560u firmware · intel/core i7 8559u firmware · intel/core i7 8550u firmware · intel/core i7 8500y firmware · intel/core i7 10510y firmware · intel/core i5 10310y firmware · intel/core i5 10210y firmware · intel/core i5 10110y firmware · intel/xeon 8253 firmware · intel/xeon 8256 firmware · intel/xeon 8260 firmware · intel/xeon 8260l firmware · intel/xeon 8260m firmware · intel/xeon 8260y firmware · intel/xeon 8268 firmware · intel/xeon 8270 firmware · +40 more
- Source
- secure@intel.com
References
- http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00016.htmlMailing List, Third Party Advisory
- https://kc.mcafee.com/corporate/index?page=content&id=SB10318Broken Link
- https://lists.debian.org/debian-lts-announce/2020/06/msg00019.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DT2VKDMQ3I37NBNJ256A2EXR7OJHXXKZ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T5OUM24ZC43G4IDT3JUCIHJTSDXJSK6Y/
- https://security.netapp.com/advisory/ntap-20200210-0004/Third Party Advisory
- https://usn.ubuntu.com/4385-1/Third Party Advisory
- https://www.debian.org/security/2020/dsa-4701Third Party Advisory
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00329.htmlVendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00016.htmlMailing List, Third Party Advisory
- https://kc.mcafee.com/corporate/index?page=content&id=SB10318Broken Link
- https://lists.debian.org/debian-lts-announce/2020/06/msg00019.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DT2VKDMQ3I37NBNJ256A2EXR7OJHXXKZ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T5OUM24ZC43G4IDT3JUCIHJTSDXJSK6Y/
- https://security.netapp.com/advisory/ntap-20200210-0004/Third Party Advisory
- https://usn.ubuntu.com/4385-1/Third Party Advisory
- https://www.debian.org/security/2020/dsa-4701Third Party Advisory
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00329.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.