CVE-2020-0545 Information
Description
Integer overflow in subsystem for Intel(R) CSME versions before 11.8.77 11.12.77 11.22.77 and Intel(R) TXE versions before 3.1.75 4.0.25 and Intel(R) Server Platform Services (SPS) versions before SPS_E5_04.01.04.380.0 SPS_SoC-X_04.00.04.128.0 SPS_SoC-A_04.00.04.211.0 SPS_E3_04.01.04.109.0 SPS_E3_04.08.04.070.0 may allow a privileged user to potentially enable denial of service via local access.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Reference
https://cert-portal.siemens.com/productcert/pdf/ssa-631949.pdf https://kc.mcafee.com/corporate/index?page=content&id=SB10321 https://security.netapp.com/advisory/ntap-20200611-0006/ https://support.lenovo.com/de/en/product_security/len-30041 https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00295.html
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction Required
HIGH
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
NONE
Base Score
HIGH
Base Severity
4.4
Share on: