First published: Wed Apr 15 2020(Updated: )
Improper buffer restrictions in firmware for some Intel(R) NUC may allow an authenticated user to potentially enable escalation of privilege via local access.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel Nuc 8 Rugged Kit Nuc8cchkr Firmware | <chaplcel.0047 | |
Intel Nuc 8 Rugged Kit Nuc8cchkr | ||
Intel Nuc Board Nuc8cchb Firmware | <chaplcel.0047 | |
Intel Nuc Board Nuc8cchb | ||
Intel Nuc 7 Essential Pc Nuc7cjysal Firmware | <jyglkcpx.86a.0053 | |
Intel Nuc 7 Essential Pc Nuc7cjysal | ||
Intel Nuc Kit Nuc7cjyh Firmware | <jyglkcpx.86a.0053 | |
Intel Nuc Kit Nuc7cjyh | ||
Intel Nuc Kit Nuc7pjyh Firmware | <jyglkcpx.86a.0053 | |
Intel Nuc Kit Nuc7pjyh | ||
Intel Nuc Kit Nuc6cays Firmware | <ayaplcel.86a0053 | |
Intel Nuc Kit Nuc6cays | ||
Intel Nuc Kit Nuc6cayh Firmware | <ayaplcel.86a0053 | |
Intel Nuc Kit Nuc6cayh | ||
Intel Nuc Kit De3815tykhe Firmware | <tybyt20h.86a.0024 | |
Intel Nuc Kit De3815tykhe | ||
Intel Nuc Board De3815tybe Firmware | <tybyt20h.86a.0024 | |
Intel Nuc Board De3815tybe | ||
Intel Compute Stick Stck1a32wfc Firmware | <fcbyt10h.86a | |
Intel Compute Stick Stck1a32wfc |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-0600 is a vulnerability in the firmware for some Intel(R) NUC that may allow an authenticated user to potentially enable escalation of privilege via local access.
The affected software includes Intel Nuc 8 Rugged Kit Nuc8cchkr firmware up to chaplcel.0047, Intel Nuc Board Nuc8cchb firmware up to chaplcel.0047, Intel Nuc 7 Essential Pc Nuc7cjysal firmware up to jyglkcpx.86a.0053, Intel Nuc Kit Nuc7cjyh firmware up to jyglkcpx.86a.0053, Intel Nuc Kit Nuc7pjyh firmware up to jyglkcpx.86a.0053, Intel Nuc Kit Nuc6cays firmware up to ayaplcel.86a0053, Intel Nuc Kit Nuc6cayh firmware up to ayaplcel.86a0053, Intel Nuc Kit De3815tykhe firmware up to tybyt20h.86a.0024, and Intel Compute Stick Stck1a32wfc firmware up to fcbyt10h.86a.
CVE-2020-0600 has a severity rating of 7.8 (high).
To fix CVE-2020-0600, update the firmware of the affected Intel(R) NUC devices to the latest version provided by Intel.
You can find more information about CVE-2020-0600 on the Intel Security Center Advisory page: [https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00363.html](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00363.html)