First published: Thu Nov 12 2020(Updated: )
Insufficient control flow management in subsystem for Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25 , Intel(R) TXE versions before 3.1.80 and 4.0.30 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel Converged Security And Manageability Engine | <11.8.80 | |
Intel Converged Security And Manageability Engine | >=11.12.0<11.12.80 | |
Intel Converged Security And Manageability Engine | >=11.22.0<11.22.80 | |
Intel Converged Security And Manageability Engine | >=12.0<12.0.70 | |
Intel Converged Security And Manageability Engine | >=14.0<14.0.45 | |
Intel Converged Security And Manageability Engine | >=14.5.0<14.5.25 | |
Intel Trusted Execution Technology | <3.1.80 | |
Intel Trusted Execution Technology | >=4.0<4.0.30 | |
Siemens Simatic Drive Controller Firmware | <05.00.01.00 | |
Siemens Simatic Drive Controller | ||
Siemens Simatic Et200sp 1515sp Pc2 Firmware | <0209.0105 | |
Siemens Simatic Et200sp 1515sp Pc2 | ||
Siemens Simatic Field Pg M5 Firmware | <22.01.08 | |
Siemens Simatic Field Pg M5 | ||
Siemens Simatic Field Pg M6 Firmware | ||
Siemens Simatic Field Pg M6 | ||
Siemens Simatic Ipc127e Firmware | <27.01.05 | |
Siemens Simatic Ipc127e | ||
Siemens Simatic Ipc427e Firmware | <27.01.05 | |
Siemens Simatic Ipc427e | ||
Siemens Simatic Ipc477e Firmware | <27.01.05 | |
Siemens Simatic Ipc477e | ||
Siemens Simatic Ipc477e Pro | ||
Siemens Simatic Ipc527g Firmware | <1.4.0 | |
Siemens Simatic Ipc527g | ||
Siemens Simatic Ipc547g Firmware | <r1.30.0 | |
Siemens Simatic Ipc547g | ||
Siemens Simatic Ipc627e Firmware | <25.02.08 | |
Siemens Simatic Ipc627e | ||
Siemens Simatic Ipc647e Firmware | <25.02.08 | |
Siemens Simatic Ipc647e | ||
Siemens Simatic Ipc667e Firmware | <25.02.08 | |
Siemens Simatic Ipc667e | ||
Siemens Simatic Ipc847e Firmware | <25.02.08 | |
Siemens Simatic Ipc847e | ||
Siemens Simatic Itp1000 Firmware | <23.01.08 | |
Siemens Simatic Itp1000 | ||
Siemens Sinumerik 828d Hw Pu.4 Firmware | <08.00.00.00 | |
Siemens Sinumerik 828d Hw Pu.4 | ||
Siemens Sinumerik Mc Mcu 1720 Firmware | <05.00.00.00 | |
Siemens Sinumerik Mc Mcu 1720 | ||
Siemens Sinumerik One Firmware | ||
Siemens Sinumerik One | ||
Siemens Sinumerik 840d Sl Ht 10 Firmware | ||
Siemens Sinumerik 840d Sl Ht 10 | ||
Siemens Sinumerik One Ncu 1740 Firmware | <04.00.00.00 | |
Siemens Sinumerik One Ncu 1740 | ||
Siemens Sinumerik One Ppu 1740 Firmware | <06.00.00.00 | |
Siemens Sinumerik One Ppu 1740 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-8745.
The severity of CVE-2020-8745 is medium.
The affected software versions for CVE-2020-8745 are Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, and Intel(R) TXE versions before 3.1.80 and 4.0.30.
An unauthenticated user may potentially enable escalation of privilege via physical access.
More information about CVE-2020-8745 can be found at the following references: [Link1](https://cert-portal.siemens.com/productcert/pdf/ssa-678983.pdf), [Link2](https://security.netapp.com/advisory/ntap-20201113-0002/), [Link3](https://security.netapp.com/advisory/ntap-20201113-0005/)