VulnerabilityModified
CVE-2020-12359
Insufficient control flow management in the firmware for some Intel(R) Processors may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
MEDIUM 6.8EPSS 0.32%
Does this matter?
Lower severity and a low EPSS score (0.32%). Track it; it rarely justifies an emergency change on its own.
Description
Insufficient control flow management in the firmware for some Intel(R) Processors may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
- CVSS 3.1
- 6.8 MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.32% probability · 25th percentile
- CISA KEV
- Not listed
- Affected
- intel/bios · netapp/cloud backup · netapp/aff bios · netapp/e-series bios · netapp/fas bios · netapp/hci compute node bios · netapp/hci storage node bios · netapp/solidfire bios
- Source
- secure@intel.com
References
- https://security.netapp.com/advisory/ntap-20210702-0002/Third Party Advisory
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00463.htmlVendor Advisory
- https://security.netapp.com/advisory/ntap-20210702-0002/Third Party Advisory
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00463.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.