5.5

CVE-2020-8698

Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Intel ≫ Microcode Version -
   Intel ≫ Core I3-1000g1 Version -
   Intel ≫ Core I3-1000g4 Version -
   Intel ≫ Core I3-1005g1 Version -
   Intel ≫ Core I3-1110g4 Version -
   Intel ≫ Core I3-1115g4 Version -
   Intel ≫ Core I3-1120g4 Version -
   Intel ≫ Core I3-1125g4 Version -
   Intel ≫ Core I5-1030g4 Version -
   Intel ≫ Core I5-1030g7 Version -
   Intel ≫ Core I5-1035g1 Version -
   Intel ≫ Core I5-1035g4 Version -
   Intel ≫ Core I5-1035g7 Version -
   Intel ≫ Core I5-1130g7 Version -
   Intel ≫ Core I5-1135g7 Version -
   Intel ≫ Core I7-1060g7 Version -
   Intel ≫ Core I7-1065g7 Version -
   Intel ≫ Core I7-1160g7 Version -
   Intel ≫ Core I7-1165g7 Version -
   Intel ≫ Core I7-1185g7 Version -
Netapp ≫ Hci Compute Node Bios Version -
   Netapp ≫ Hci Compute Node Version -
Netapp ≫ Hci Storage Node Bios Version -
   Netapp ≫ Hci Storage Node Version -
Netapp ≫ Solidfire Bios Version -
   Netapp ≫ Solidfire Version -
Fedoraproject ≫ Fedora Version 31
Debian ≫ Debian Linux Version 9.0
Siemens ≫ Simatic Field Pg M5 Firmware Version < 22.01.08
   Siemens ≫ Simatic Field Pg M5 Version -
Siemens ≫ Simatic Ipc427e Firmware Version < 21.01.15
   Siemens ≫ Simatic Ipc427e Version -
Siemens ≫ Simatic Ipc477e Firmware Version < 21.01.15
   Siemens ≫ Simatic Ipc477e Version -
Siemens ≫ Simatic Ipc477e Pro Firmware Version < 21.01.15
   Siemens ≫ Simatic Ipc477e Pro Version -
Siemens ≫ Simatic Ipc627e Firmware Version < 25.02.08
   Siemens ≫ Simatic Ipc627e Version -
Siemens ≫ Simatic Ipc647e Firmware Version < 25.02.08
   Siemens ≫ Simatic Ipc647e Version -
Siemens ≫ Simatic Ipc677e Firmware Version < 25.02.08
   Siemens ≫ Simatic Ipc677e Version -
Siemens ≫ Simatic Ipc847e Firmware Version < 25.02.08
   Siemens ≫ Simatic Ipc847e Version -
Siemens ≫ Simatic Itp1000 Firmware Version < 23.01.08
   Siemens ≫ Simatic Itp1000 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.52% 0.411
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
NIST 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE-668 Exposure of Resource to Wrong Sphere

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

https://cert-portal.siemens.com/productcert/pdf/ssa-678983.pdf
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2021/02/msg00007.html
Third Party Advisory
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MAAGIK5CXKBPGY3R4UR5VO56M7MKLZ43/
https://security.netapp.com/advisory/ntap-20201113-0006/
Third Party Advisory
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00381
Vendor Advisory