CVE-2020-12300: High severity intel server board s2600cw2 firmware vulnerability
Published Aug 13, 2020
·Updated
Uninitialized pointer in BIOS firmware for Intel(R) Server Board Families S2600CW, S2600KP, S2600TP, and S2600WT may allow a privileged user to potentially enable escalation of privilege via local access.
Affected Software
46 affected components
Intel S2600cw2 Firmware<01.01.0029
Intel S2600cw2
Intel S2600cw2s Firmware<01.01.0029
Intel S2600cw2s
Intel S2600cwt Firmware<01.01.0029
Intel S2600cwt
Intel S2600cwts Firmware<01.01.0029
Intel S2600cwts
Intel S2600cw2r Firmware<01.01.0029
Intel S2600cw2r
Intel S2600cw2sr Firmware<01.01.0029
Intel S2600cw2sr
Intel S2600cwtr Firmware<01.01.0029
Intel S2600cwtr
Intel S2600cwtsr Firmware<01.01.0029
Intel S2600cwtsr
Intel S2600kp Firmware<01.01.0029
Intel S2600KP
Intel S2600kpf Firmware<01.01.0029
Intel S2600kpf
Intel S2600kpr Firmware<01.01.0029
Intel S2600kpr
Intel S2600kpfr Firmware<01.01.0029
Intel S2600kpfr
Intel S2600kptr Firmware<01.01.0029
Intel S2600kptr
Intel S2600tp Firmware<01.01.0029
Intel S2600TP
Intel S2600tpf Firmware<01.01.0029
Intel S2600tpf
Intel S2600tpfr Firmware<01.01.0029
Intel S2600tpfr
Intel S2600tpnr Firmware<01.01.0029
Intel S2600tpnr
Intel S2600tpr Firmware<01.01.0029
Intel S2600tpr
Intel S2600wt2 Firmware<01.01.0029
Intel S2600wt2
Intel S2600wtt Firmware<01.01.0029
Intel S2600wtt
Intel S2600wttr Firmware<01.01.0029
Intel S2600wttr
Intel S2600wt2r Firmware<01.01.0029
Intel S2600wt2r
Intel S2600wtts1r Firmware<01.01.0029
Intel S2600wtts1r
Remediation
Event History
Aug 13, 2020
CVE Published
via MITRE·03:25 AM
Data Sourced
via MITRE·03:25 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2020-12300?
CVE-2020-12300 is a vulnerability in the BIOS firmware for Intel(R) Server Board Families S2600CW, S2600KP, S2600TP, and S2600WT.
2
How can a privileged user potentially exploit CVE-2020-12300?
A privileged user with local access could potentially enable escalation of privilege using CVE-2020-12300.
3
What is the severity of CVE-2020-12300?
CVE-2020-12300 has a severity score of 8.2 (high severity).
4
Which Intel Server Board Families are affected by CVE-2020-12300?
Intel(R) Server Board Families S2600CW, S2600KP, S2600TP, and S2600WT are affected by CVE-2020-12300.
5
How can I fix CVE-2020-12300?
To fix CVE-2020-12300, it is recommended to update the BIOS firmware for the affected Intel Server Board Families to version 01.01.0029 or newer.