First published: Thu Oct 22 2020(Updated: )
A flaw was found in the CPU microarchitecture where a local attacker is able to abuse a timing issue which may allow them to infer internal architectural state from previous executions on the CPU.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microcode | ||
Intel Core i3-1000G1 Firmware | ||
Intel Core i3-1000G4 Firmware | ||
Intel Core i3-1005G1 firmware | ||
Intel Core i3-1110G4 Firmware | ||
Intel Core i3-1115G4 Firmware | ||
Intel Core i3-1120G4 Firmware | ||
Intel Core i3-1125G4 Firmware | ||
Intel Core i5-1030G4 Firmware | ||
Intel Core i5-1030NG7 Firmware | ||
Intel Core i5-1035G1 | ||
Intel Core i5-1035G4 | ||
Intel Core i5-1035G7 Firmware | ||
Intel Core i5-1130G7 Firmware | ||
Intel Core i5-1135G7 Firmware | ||
Intel Core i7-1060G7 Firmware | ||
Intel Core i7-1065G7 Firmware | ||
Intel Core i7-1160G7 Firmware | ||
Intel Core i7-1165G7 Firmware | ||
Intel Core i7-1185G7 Firmware | ||
IBM Data ONTAP | ||
NetApp HCI Compute Node BIOS | ||
NetApp HCI Compute Node | ||
NetApp HCI Storage Node | ||
NetApp HCI Storage Nodes | ||
NetApp SolidFire | ||
NetApp SolidFire & HCI Storage Node | ||
Red Hat Fedora | =31 | |
Debian Linux | =9.0 | |
Siemens Simatic Field PG M5 | <22.01.08 | |
Siemens Simatic Field PG M5 | ||
Siemens Simatic Field PG M6 Firmware | ||
Siemens Simatic Field PG M6 Firmware | ||
Siemens Simatic IPC427E Firmware | <21.01.15 | |
Siemens Simatic IPC427E Firmware | ||
Siemens Simatic IPC477E Firmware | <21.01.15 | |
Siemens Simatic IPC477E Firmware | ||
Siemens Simatic IPC477E Pro | <21.01.15 | |
Siemens Simatic IPC477E Firmware | ||
Siemens Simatic IPC627E Firmware | <25.02.08 | |
Siemens Simatic IPC627E Firmware | ||
Siemens Simatic IPC647E Firmware | <25.02.08 | |
Siemens Simatic IPC647E Firmware | ||
Siemens Simatic IPC677E Firmware | <25.02.08 | |
Siemens Simatic IPC677E Firmware | ||
Siemens Simatic IPC847E Firmware | <25.02.08 | |
Siemens Simatic IPC847E Firmware | ||
Siemens Simatic ITP1000 | <23.01.08 | |
Siemens Simatic ITP1000 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2020-8698 is a vulnerability in the CPU microarchitecture that allows a local attacker to infer internal architectural state from previous executions on the CPU.
Intel Microcode, NetApp Clustered Data ONTAP, Netapp Hci Compute Node Bios, Netapp Hci Storage Node Bios, Netapp Solidfire Bios, Fedoraproject Fedora, Debian Debian Linux, Siemens Simatic Field Pg M5 Firmware, Siemens Simatic Field Pg M6 Firmware, Siemens Simatic Ipc427e Firmware, Siemens Simatic Ipc477e Firmware, Siemens Simatic Ipc477e Pro Firmware, Siemens Simatic Ipc627e Firmware, Siemens Simatic Ipc647e Firmware, Siemens Simatic Ipc677e Firmware, Siemens Simatic Ipc847e Firmware, Siemens Simatic Itp1000 Firmware are affected by CVE-2020-8698.
CVE-2020-8698 has a severity score of 5.5 (medium).
No, Intel Core I3-1000g1 is not vulnerable to CVE-2020-8698.
To fix CVE-2020-8698, it is recommended to apply the necessary patches and microcode updates provided by the software vendors.