6.7

CVE-2020-8710

Buffer overflow in the bootloader for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.45 may allow a privileged user to potentially enable escalation of privilege via local access.

Data is provided by the National Vulnerability Database (NVD)
IntelServer Board S2600wt Firmware Version < 2.45
   IntelServer Board S2600wt2 Version-
   IntelServer Board S2600wt2r Version-
   IntelServer Board S2600wtt Version-
   IntelServer Board S2600wttr Version-
IntelServer System R1000wt Firmware Version < 2.45
   IntelServer System R1208wt2gs Version-
   IntelServer System R1208wt2gsr Version-
   IntelServer System R1208wttgs Version-
   IntelServer System R1208wttgsbpp Version-
   IntelServer System R1208wttgsr Version-
   IntelServer System R1304wt2gs Version-
   IntelServer System R1304wt2gsr Version-
   IntelServer System R1304wttgs Version-
   IntelServer System R1304wttgsr Version-
IntelServer System R2000wt Firmware Version < 2.45
   IntelServer System R2208wt2ys Version-
   IntelServer System R2208wt2ysr Version-
   IntelServer System R2208wttyc1 Version-
   IntelServer System R2208wttyc1r Version-
   IntelServer System R2208wttys Version-
   IntelServer System R2208wttysr Version-
   IntelServer System R2224wttys Version-
   IntelServer System R2224wttysr Version-
   IntelServer System R2308wttys Version-
   IntelServer System R2308wttysr Version-
   IntelServer System R2312wttys Version-
   IntelServer System R2312wttysr Version-
IntelServer Board S2600cw Version < 2.45
   IntelServer Board S2600cw2 Version-
   IntelServer Board S2600cw2r Version-
   IntelServer Board S2600cw2s Version-
   IntelServer Board S2600cw2sr Version-
   IntelServer Board S2600cwt Version-
   IntelServer Board S2600cwtr Version-
   IntelServer Board S2600cwts Version-
   IntelServer Board S2600cwtsr Version-
IntelServer Board S2600kp Firmware Version < 2.45
   IntelServer Board S2600kp Version-
   IntelServer Board S2600kpf Version-
   IntelServer Board S2600kpfr Version-
   IntelServer Board S2600kpr Version-
   IntelServer Board S2600kptr Version-
IntelCompute Module S2600tp Firmware Version < 2.45
   IntelServer Board S2600tp Version-
   IntelServer Board S2600tpf Version-
   IntelServer Board S2600tpfr Version-
   IntelServer Board S2600tpr Version-
IntelServer Board S1200sp Firmware Version < 2.45
   IntelServer Board S1200spl Version-
   IntelServer Board S1200splr Version-
   IntelServer Board S1200spo Version-
   IntelServer Board S1200spor Version-
   IntelServer Board S1200sps Version-
   IntelServer Board S1200spsr Version-
IntelServer Board S2600wf Firmware Version < 2.45
   IntelServer Board S2600wf0 Version-
   IntelServer Board S2600wf0r Version-
   IntelServer Board S2600wfq Version-
   IntelServer Board S2600wfqr Version-
   IntelServer Board S2600wft Version-
   IntelServer Board S2600wftr Version-
IntelServer System R1000wf Firmware Version < 2.45
   IntelServer System Lnetcnt3y Version-
   IntelServer System Mcb2208wfaf4 Version-
   IntelServer System Mcb2208wfaf5 Version-
   IntelServer System Mcb2208wfaf6 Version-
   IntelServer System Mcb2208wfhy2 Version-
   IntelServer System Nb2208wfqnfvi Version-
   IntelServer System R1208wfqysr Version-
   IntelServer System R1208wftys Version-
   IntelServer System R1208wftysr Version-
   IntelServer System R1304wf0ys Version-
   IntelServer System R1304wf0ysr Version-
   IntelServer System R1304wftys Version-
   IntelServer System R1304wftysr Version-
IntelServer System R2000wf Firmware Version < 2.45
   IntelServer System R2208wf0zs Version-
   IntelServer System R2208wf0zsr Version-
   IntelServer System R2208wfqzs Version-
   IntelServer System R2208wfqzsr Version-
   IntelServer System R2208wftzs Version-
   IntelServer System R2208wftzsr Version-
   IntelServer System R2224wfqzs Version-
   IntelServer System R2224wftzs Version-
   IntelServer System R2224wftzsr Version-
   IntelServer System R2308wftzs Version-
   IntelServer System R2308wftzsr Version-
   IntelServer System R2312wf0np Version-
   IntelServer System R2312wf0npr Version-
   IntelServer System R2312wfqzs Version-
   IntelServer System R2312wftzs Version-
   IntelServer System R2312wftzsr Version-
   IntelServer System Vrn2208waf6 Version-
   IntelServer System Vrn2208wfaf81 Version-
   IntelServer System Vrn2208wfaf82 Version-
   IntelServer System Vrn2208wfaf83 Version-
   IntelServer System Vrn2208wfhy6 Version-
IntelServer Board S2600st Firmware Version < 2.45
   IntelServer Board S2600stb Version-
   IntelServer Board S2600stbr Version-
   IntelServer Board S2600stq Version-
   IntelServer Board S2600stqr Version-
IntelCompute Module Hns2600bp Firmware Version < 2.45
   IntelCompute Module Hns2600bpb Version-
   IntelCompute Module Hns2600bpb24 Version-
   IntelCompute Module Hns2600bpb24r Version-
   IntelCompute Module Hns2600bpblc Version-
   IntelCompute Module Hns2600bpblc24 Version-
   IntelCompute Module Hns2600bpblc24r Version-
   IntelCompute Module Hns2600bpblcr Version-
   IntelCompute Module Hns2600bpbr Version-
   IntelCompute Module Hns2600bpq Version-
   IntelCompute Module Hns2600bpq24 Version-
   IntelCompute Module Hns2600bpq24r Version-
   IntelCompute Module Hns2600bpqr Version-
   IntelCompute Module Hns2600bps Version-
   IntelCompute Module Hns2600bps24 Version-
   IntelCompute Module Hns2600bps24r Version-
   IntelCompute Module Hns2600bpsr Version-
IntelServer Board S2600bp Firmware Version < 2.45
   IntelServer Board S2600bpb Version-
   IntelServer Board S2600bpbr Version-
   IntelServer Board S2600bpq Version-
   IntelServer Board S2600bpqr Version-
   IntelServer Board S2600bps Version-
   IntelServer Board S2600bpsr Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.19% 0.384
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.