First published: Thu Nov 12 2020(Updated: )
Insecure default variable initialization in firmware for some Intel(R) NUCs may allow an authenticated user to potentially enable escalation of privilege via local access.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel Nuc 8 Mainstream-g Kit Nuc8i5inh Firmware | =inwhl357.0036 | |
Intel Nuc 8 Mainstream-g Kit Nuc8i5inh | ||
Intel Nuc 8 Mainstream-g Kit Nuc8i7inh Firmware | =inwhl357.0036 | |
Intel Nuc 8 Mainstream-g Kit Nuc8i7inh | ||
Intel Nuc 8 Mainstream-g Mini Pc Nuc8i5inh Firmware | =inwhl357.0036 | |
Intel Nuc 8 Mainstream-g Mini Pc Nuc8i5inh | ||
Intel Nuc 8 Mainstream-g Mini Pc Nuc8i7inh Firmware | =inwhl357.0036 | |
Intel Nuc 8 Mainstream-g Mini Pc Nuc8i7inh | ||
Intel Nuc 8 Pro Board Nuc8i3pnb Firmware | =pnwhl357.0037 | |
Intel Nuc 8 Pro Board Nuc8i3pnb | ||
Intel Nuc 8 Pro Kit Nuc8i3pnh Firmware | =pnwhl357.0037 | |
Intel Nuc 8 Pro Kit Nuc8i3pnh | ||
Intel Nuc 8 Pro Kit Nuc8i3pnk Firmware | =pnwhl357.0037 | |
Intel Nuc 8 Pro Kit Nuc8i3pnk | ||
Intel Nuc 8 Pro Mini Pc Nuc8i3pnk Firmware | =pnwhl357.0037 | |
Intel Nuc 8 Pro Mini Pc Nuc8i3pnk | ||
Intel Nuc 8 Rugged Kit Nuc8cchkr Firmware | =chaplcel.0049 | |
Intel Nuc 8 Rugged Kit Nuc8cchkr | ||
Intel Nuc 9 Pro Kit Nuc9v7qnx Firmware | =qncflx70.34 | |
Intel Nuc 9 Pro Kit Nuc9v7qnx | ||
Intel Nuc 9 Pro Kit Nuc9vxqnx Firmware | =qncflx70.34 | |
Intel Nuc 9 Pro Kit Nuc9vxqnx | ||
Intel Nuc Board H27002-400 Firmware | =tybyt10h.86a | |
Intel Nuc Board H27002-400 | ||
Intel Nuc Board H27002-401 Firmware | =tybyt10h.86a | |
Intel Nuc Board H27002-401 | ||
Intel Nuc Board H27002-402 Firmware | =tybyt10h.86a | |
Intel Nuc Board H27002-402 | ||
Intel Nuc Board H27002-404 Firmware | =tybyt10h.86a | |
Intel Nuc Board H27002-404 | ||
Intel Nuc Board H27002-500 Firmware | =tybyt20h.86a | |
Intel Nuc Board H27002-500 | ||
Intel Nuc Board Nuc8cchb Firmware | =chaplcel.0049 | |
Intel Nuc Board Nuc8cchb | ||
Intel Nuc Kit H26998-401 Firmware | =tybyt10h.86a | |
Intel Nuc Kit H26998-401 | ||
Intel Nuc Kit H26998-402 Firmware | =tybyt10h.86a | |
Intel Nuc Kit H26998-402 | ||
Intel Nuc Kit H26998-403 Firmware | =tybyt10h.86a | |
Intel Nuc Kit H26998-403 | ||
Intel Nuc Kit H26998-404 Firmware | =tybyt10h.86a | |
Intel Nuc Kit H26998-404 | ||
Intel Nuc Kit H26998-405 Firmware | =tybyt10h.86a | |
Intel Nuc Kit H26998-405 | ||
Intel Nuc Kit H26998-500 Firmware | =tybyt20h.86a | |
Intel Nuc Kit H26998-500 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-12336.
CVE-2020-12336 is an insecure default variable initialization vulnerability in firmware for some Intel NUCs that may allow an authenticated user to potentially enable escalation of privilege via local access.
Some Intel NUCs are affected by CVE-2020-12336. The specific affected software versions can be found in the affected software section of the vulnerability description.
The severity of CVE-2020-12336 is high with a CVSS score of 7.8.
To fix CVE-2020-12336, it is recommended to apply the firmware update provided by Intel. Please refer to the reference link for more information.