VulnerabilityModified
CVE-2020-8730
Heap-based overflow for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow an authenticated user to potentially enable escalation of privilege via local access.
HIGH 8.8EPSS 0.35%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.35%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Heap-based overflow for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- EPSS
- 0.35% probability · 28th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-787
- Affected
- intel/server board s2600wt firmware · intel/server system r1000wt firmware · intel/server system r2000wt firmware · intel/server board s2600cw · intel/compute module hns2600kp firmware · intel/server board s2600kp firmware · intel/compute module hns2600tp firmware · intel/compute module s2600tp firmware · intel/server board s1200sp firmware · intel/server system lr1304sp firmware · intel/server system lsvrp firmware · intel/server system r1000sp firmware · intel/server board s2600wf firmware · intel/server system r1000wf firmware · intel/server system r2000wf firmware · intel/server board s2600st firmware · intel/compute module hns2600bp firmware · intel/server board s2600bp firmware
- Source
- secure@intel.com
References
- https://security.netapp.com/advisory/ntap-20200814-0002/Third Party Advisory
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00384.htmlVendor Advisory
- https://security.netapp.com/advisory/ntap-20200814-0002/Third Party Advisory
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00384.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.