First published: Thu Nov 12 2020(Updated: )
Insufficient control flow management in subsystem for Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25 , Intel(R) TXE versions before 3.1.80 and 4.0.30 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel Converged Security and Manageability Engine | <11.8.80 | |
Intel Converged Security and Manageability Engine | >=11.12.0<11.12.80 | |
Intel Converged Security and Manageability Engine | >=11.22.0<11.22.80 | |
Intel Converged Security and Manageability Engine | >=12.0<12.0.70 | |
Intel Converged Security and Manageability Engine | >=14.0<14.0.45 | |
Intel Converged Security and Manageability Engine | >=14.5.0<14.5.25 | |
Intel Trusted Execution Technology | <3.1.80 | |
Intel Trusted Execution Technology | >=4.0<4.0.30 | |
Siemens SIMATIC Drive Controller Firmware | <05.00.01.00 | |
Siemens SIMATIC Drive Controller Firmware | ||
Siemens SIMATIC ET 200SP Open Controller CPU 1515SP PC2 Firmware | <0209.0105 | |
Siemens Simatic ET 200SP 1515SP PC2 | ||
Siemens Simatic Field PG M5 | <22.01.08 | |
Siemens Simatic Field PG M5 | ||
Siemens Simatic Field PG M6 Firmware | ||
Siemens Simatic Field PG M6 Firmware | ||
Siemens Simatic IPC127E Firmware | <27.01.05 | |
Siemens Simatic IPC127E Firmware | ||
Siemens Simatic IPC427E Firmware | <27.01.05 | |
Siemens Simatic IPC427E Firmware | ||
Siemens Simatic IPC477E Firmware | <27.01.05 | |
Siemens Simatic IPC477E Firmware | ||
Siemens Simatic IPC477E Firmware | ||
Siemens Simatic IPC527G | <1.4.0 | |
Siemens Simatic IPC527G Firmware | ||
Siemens Simatic IPC547G | <r1.30.0 | |
Siemens Simatic IPC547G Firmware | ||
Siemens Simatic IPC627E Firmware | <25.02.08 | |
Siemens Simatic IPC627E Firmware | ||
Siemens Simatic IPC647E Firmware | <25.02.08 | |
Siemens Simatic IPC647E Firmware | ||
Siemens Simatic IPC667E | <25.02.08 | |
Siemens Simatic IPC667E | ||
Siemens Simatic IPC847E Firmware | <25.02.08 | |
Siemens Simatic IPC847E Firmware | ||
Siemens Simatic ITP1000 | <23.01.08 | |
Siemens Simatic ITP1000 Firmware | ||
Siemens Sinumerik 828D Firmware | <08.00.00.00 | |
Siemens Sinumerik 828D | ||
Siemens Sinumerik MC Firmware | <05.00.00.00 | |
Siemens Sinumerik MC MCU 1720 | ||
Siemens Sinumerik One Firmware | ||
Siemens Sinumerik One | ||
Siemens Sinumerik 840D SL Firmware | ||
Siemens Sinumerik 840D SL | ||
Siemens Sinumerik One Firmware | <04.00.00.00 | |
Siemens Sinumerik One Firmware | ||
Siemens Sinumerik One Firmware | <06.00.00.00 | |
Siemens Sinumerik One Firmware | ||
All of | ||
Siemens SIMATIC Drive Controller Firmware | <05.00.01.00 | |
Siemens SIMATIC Drive Controller Firmware | ||
All of | ||
Siemens SIMATIC ET 200SP Open Controller CPU 1515SP PC2 Firmware | <0209.0105 | |
Siemens Simatic ET 200SP 1515SP PC2 | ||
All of | ||
Siemens Simatic Field PG M5 | <22.01.08 | |
Siemens Simatic Field PG M5 | ||
All of | ||
Siemens Simatic Field PG M6 Firmware | ||
Siemens Simatic Field PG M6 Firmware | ||
All of | ||
Siemens Simatic IPC127E Firmware | <27.01.05 | |
Siemens Simatic IPC127E Firmware | ||
All of | ||
Siemens Simatic IPC427E Firmware | <27.01.05 | |
Siemens Simatic IPC427E Firmware | ||
All of | ||
Siemens Simatic IPC477E Firmware | <21.01.15 | |
Any of | ||
Siemens Simatic IPC477E Firmware | ||
Siemens Simatic IPC477E Firmware | ||
All of | ||
Siemens Simatic IPC527G | <1.4.0 | |
Siemens Simatic IPC527G Firmware | ||
All of | ||
Siemens Simatic IPC547G | <r1.30.0 | |
Siemens Simatic IPC547G Firmware | ||
All of | ||
Siemens Simatic IPC627E Firmware | <25.02.08 | |
Siemens Simatic IPC627E Firmware | ||
All of | ||
Siemens Simatic IPC647E Firmware | <25.02.08 | |
Siemens Simatic IPC647E Firmware | ||
All of | ||
Siemens Simatic IPC667E | <25.02.08 | |
Siemens Simatic IPC667E | ||
All of | ||
Siemens Simatic IPC847E Firmware | <25.02.08 | |
Siemens Simatic IPC847E Firmware | ||
All of | ||
Siemens Simatic ITP1000 | <23.01.08 | |
Siemens Simatic ITP1000 Firmware | ||
All of | ||
Siemens Sinumerik 828D Firmware | <08.00.00.00 | |
Siemens Sinumerik 828D | ||
All of | ||
Siemens Sinumerik MC Firmware | <05.00.00.00 | |
Siemens Sinumerik MC MCU 1720 | ||
All of | ||
Siemens Sinumerik One Firmware | ||
Siemens Sinumerik One | ||
All of | ||
Siemens Sinumerik 840D SL Firmware | ||
Siemens Sinumerik 840D SL | ||
All of | ||
Siemens Sinumerik One Firmware | <04.00.00.00 | |
Siemens Sinumerik One Firmware | ||
All of | ||
Siemens Sinumerik One Firmware | <06.00.00.00 | |
Siemens Sinumerik One Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-8745.
The severity of CVE-2020-8745 is medium.
The affected software versions for CVE-2020-8745 are Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, and Intel(R) TXE versions before 3.1.80 and 4.0.30.
An unauthenticated user may potentially enable escalation of privilege via physical access.
More information about CVE-2020-8745 can be found at the following references: [Link1](https://cert-portal.siemens.com/productcert/pdf/ssa-678983.pdf), [Link2](https://security.netapp.com/advisory/ntap-20201113-0002/), [Link3](https://security.netapp.com/advisory/ntap-20201113-0005/)