First published: Thu Nov 12 2020(Updated: )
Insecure default variable initialization in firmware for some Intel(R) NUCs may allow an authenticated user to potentially enable escalation of privilege via local access.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel NUC 8 Mainstream-G Kit NUC8i5INH | =inwhl357.0036 | |
Intel NUC 8 Mainstream-G Kit | ||
Intel NUC 8 Mainstream Game Kit Firmware | =inwhl357.0036 | |
Intel NUC 8 Mainstream-G Kit | ||
Intel NUC 8 Mainstream-G Mini PC NUC8i5INH | =inwhl357.0036 | |
Intel NUC 8 Mainstream-G Kit NUC8i5INH | ||
Intel NUC 8 Mainstream-G | =inwhl357.0036 | |
Intel NUC 8 Mainstream-G Mini PC NUC8i7INH Firmware | ||
Intel NUC8i3PNB Firmware | =pnwhl357.0037 | |
Intel NUC Pro Board NUC8i3PNB | ||
Intel NUC Pro Board NUC8i3PNH Firmware | =pnwhl357.0037 | |
Intel NUC Pro Kit NUC8i3PNH | ||
Intel NUC 8 Pro Mini PC NUC8i3PNK Firmware | =pnwhl357.0037 | |
Intel NUC Pro Kit NUC8i3PNK | ||
Intel NUC Pro Board NUC8i3PNK Firmware | =pnwhl357.0037 | |
Intel NUC Pro Kit NUC8i3PNK Firmware | ||
Intel NUC Rugged Kit NUC8CCHKR | =chaplcel.0049 | |
Intel NUC Rugged Kit NUC8CCHKR | ||
Intel NUC Pro Compute Element NUC9V7QNX Firmware | =qncflx70.34 | |
Intel NUC 9 V7 QNX | ||
Intel NUC 9 Pro Compute Element | =qncflx70.34 | |
Intel NUC 9 Pro Kit NUC9VXQNX Firmware | ||
Intel NUC board h27002-400 firmware | =tybyt10h.86a | |
Intel NUC board h27002-400 firmware | ||
Intel NUC board h27002-401 | =tybyt10h.86a | |
Intel NUC board h27002-401 firmware | ||
Intel NUC Board H27002-402 | =tybyt10h.86a | |
Intel NUC Board H27002-402 | ||
Intel NUC Board H27002-404 Firmware | =tybyt10h.86a | |
Intel NUC board h27002-404 firmware | ||
Intel NUC board h27002-500 | =tybyt20h.86a | |
Intel NUC | ||
Intel NUC 8 CCHB Firmware | =chaplcel.0049 | |
Intel NUC 8 CCHB Firmware | ||
Intel NUC | =tybyt10h.86a | |
Intel NUC Kit H26998 | ||
Intel NUC Kit | =tybyt10h.86a | |
Intel NUC kit h26998-402 firmware | ||
Intel NUC Kit firmware | =tybyt10h.86a | |
Intel NUC kit | ||
Intel NUC | =tybyt10h.86a | |
Intel NUC Kit | ||
Intel NUC Kit firmware | =tybyt10h.86a | |
Intel NUC kit h26998-405 firmware | ||
Intel NUC Kit H26998-500 Firmware | =tybyt20h.86a | |
Intel NUC kit h26998-500 firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-12336.
CVE-2020-12336 is an insecure default variable initialization vulnerability in firmware for some Intel NUCs that may allow an authenticated user to potentially enable escalation of privilege via local access.
Some Intel NUCs are affected by CVE-2020-12336. The specific affected software versions can be found in the affected software section of the vulnerability description.
The severity of CVE-2020-12336 is high with a CVSS score of 7.8.
To fix CVE-2020-12336, it is recommended to apply the firmware update provided by Intel. Please refer to the reference link for more information.