6.8

CVE-2020-8745

Insufficient control flow management in subsystem for Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25 , Intel(R) TXE versions before 3.1.80 and 4.0.30 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

Data is provided by the National Vulnerability Database (NVD)
IntelConverged Security And Manageability Engine Version >= 11.12.0 < 11.12.80
IntelConverged Security And Manageability Engine Version >= 11.22.0 < 11.22.80
IntelConverged Security And Manageability Engine Version >= 12.0 < 12.0.70
IntelConverged Security And Manageability Engine Version >= 14.0 < 14.0.45
IntelConverged Security And Manageability Engine Version >= 14.5.0 < 14.5.25
IntelTrusted Execution Technology Version < 3.1.80
IntelTrusted Execution Technology Version >= 4.0 < 4.0.30
SiemensSimatic Drive Controller Firmware Version < 05.00.01.00
   SiemensSimatic Drive Controller Version-
SiemensSimatic Field Pg M5 Firmware Version < 22.01.08
   SiemensSimatic Field Pg M5 Version-
SiemensSimatic Ipc127e Firmware Version < 27.01.05
   SiemensSimatic Ipc127e Version-
SiemensSimatic Ipc427e Firmware Version < 27.01.05
   SiemensSimatic Ipc427e Version-
SiemensSimatic Ipc477e Firmware Version < 21.01.15
   SiemensSimatic Ipc477e Version-
   SiemensSimatic Ipc477e Pro Version-
SiemensSimatic Ipc527g Firmware Version < 1.4.0
   SiemensSimatic Ipc527g Version-
SiemensSimatic Ipc547g Firmware Version < r1.30.0
   SiemensSimatic Ipc547g Version-
SiemensSimatic Ipc627e Firmware Version < 25.02.08
   SiemensSimatic Ipc627e Version-
SiemensSimatic Ipc647e Firmware Version < 25.02.08
   SiemensSimatic Ipc647e Version-
SiemensSimatic Ipc667e Firmware Version < 25.02.08
   SiemensSimatic Ipc667e Version-
SiemensSimatic Ipc847e Firmware Version < 25.02.08
   SiemensSimatic Ipc847e Version-
SiemensSimatic Itp1000 Firmware Version < 23.01.08
   SiemensSimatic Itp1000 Version-
SiemensSinumerik 828d Hw Pu.4 Firmware Version < 08.00.00.00
   SiemensSinumerik 828d Hw Pu.4 Version-
SiemensSinumerik Mc Mcu 1720 Firmware Version < 05.00.00.00
   SiemensSinumerik Mc Mcu 1720 Version-
SiemensSinumerik One Firmware Version-
   SiemensSinumerik One Version-
SiemensSinumerik One Ncu 1740 Firmware Version < 04.00.00.00
   SiemensSinumerik One Ncu 1740 Version-
SiemensSinumerik One Ppu 1740 Firmware Version < 06.00.00.00
   SiemensSinumerik One Ppu 1740 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.36% 0.573
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.8 0.9 5.9
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P