SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-8694

Insufficient access control in the Linux kernel driver for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

MEDIUM 5.5EPSS 0.45%

Does this matter?

Lower severity and a low EPSS score (0.45%). Track it; it rarely justifies an emergency change on its own.

Description

Insufficient access control in the Linux kernel driver for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVSS 3.1
5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
0.45% probability · 38th percentile
CISA KEV
Not listed
Affected
intel/core i7-8510y firmware · intel/core i7-8500y firmware · intel/core i5-8310y firmware · intel/core i5-8210y firmware · intel/core i5-8200y firmware · intel/core m3-8100y firmware · intel/core i7-7500u firmware · intel/core i7-7510u firmware · intel/core i7-7600u firmware · intel/core i5-7200u firmware · intel/core i5-7210u firmware · intel/core i5-7300u firmware · intel/core i5-7500u firmware · intel/core i3-7007u firmware · intel/core i3-7100u firmware · intel/core i3-7110u firmware · intel/core i3-7130u firmware · intel/pentium 4415u firmware · intel/celeron 3865u firmware · intel/celeron 3965u firmware · +40 more
Source
secure@intel.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.