VulnerabilityModified
CVE-2020-8694
Insufficient access control in the Linux kernel driver for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
MEDIUM 5.5EPSS 0.45%
Does this matter?
Lower severity and a low EPSS score (0.45%). Track it; it rarely justifies an emergency change on its own.
Description
Insufficient access control in the Linux kernel driver for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.45% probability · 38th percentile
- CISA KEV
- Not listed
- Affected
- intel/core i7-8510y firmware · intel/core i7-8500y firmware · intel/core i5-8310y firmware · intel/core i5-8210y firmware · intel/core i5-8200y firmware · intel/core m3-8100y firmware · intel/core i7-7500u firmware · intel/core i7-7510u firmware · intel/core i7-7600u firmware · intel/core i5-7200u firmware · intel/core i5-7210u firmware · intel/core i5-7300u firmware · intel/core i5-7500u firmware · intel/core i3-7007u firmware · intel/core i3-7100u firmware · intel/core i3-7110u firmware · intel/core i3-7130u firmware · intel/pentium 4415u firmware · intel/celeron 3865u firmware · intel/celeron 3965u firmware · +40 more
- Source
- secure@intel.com
References
- https://cert-portal.siemens.com/productcert/pdf/ssa-678983.pdf
- https://lists.debian.org/debian-lts-announce/2020/12/msg00015.html
- https://lists.debian.org/debian-lts-announce/2020/12/msg00027.html
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00389Vendor Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-678983.pdf
- https://lists.debian.org/debian-lts-announce/2020/12/msg00015.html
- https://lists.debian.org/debian-lts-announce/2020/12/msg00027.html
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00389Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.