Vulnerabilities > Intel > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-08-13 CVE-2020-8711 Unspecified vulnerability in Intel products
Improper access control in the bootloader for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.45 may allow a privileged user to potentially enable escalation of privilege via local access.
local
low complexity
intel
6.7
2020-08-13 CVE-2020-8710 Classic Buffer Overflow vulnerability in Intel products
Buffer overflow in the bootloader for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.45 may allow a privileged user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-120
6.7
2020-08-13 CVE-2019-14630 Unspecified vulnerability in Intel products
Reliance on untrusted inputs in a security decision in some Intel(R) Thunderbolt(TM) controllers may allow unauthenticated user to potentially enable information disclosure via physical access.
low complexity
intel
4.6
2020-06-15 CVE-2020-8675 Unspecified vulnerability in Intel Innovation Engine Firmware
Insufficient control flow management in firmware build and signing tool for Intel(R) Innovation Engine before version 1.0.859 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
low complexity
intel
6.8
2020-06-15 CVE-2020-8674 Out-of-bounds Read vulnerability in Intel products
Out-of-bounds read in DHCPv6 subsystem in Intel(R) AMT and Intel(R)ISM versions before 11.8.77, 11.12.77, 11.22.77, 12.0.64 and 14.0.33 may allow an unauthenticated user to potentially enable information disclosure via network access.
network
low complexity
intel CWE-125
5.3
2020-06-15 CVE-2020-0566 Unspecified vulnerability in Intel Trusted Execution Engine Firmware
Improper Access Control in subsystem for Intel(R) TXE versions before 3.175 and 4.0.25 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
low complexity
intel
6.8
2020-06-15 CVE-2020-0545 Integer Overflow or Wraparound vulnerability in Intel products
Integer overflow in subsystem for Intel(R) CSME versions before 11.8.77, 11.12.77, 11.22.77 and Intel(R) TXE versions before 3.1.75, 4.0.25 and Intel(R) Server Platform Services (SPS) versions before SPS_E5_04.01.04.380.0, SPS_SoC-X_04.00.04.128.0, SPS_SoC-A_04.00.04.211.0, SPS_E3_04.01.04.109.0, SPS_E3_04.08.04.070.0 may allow a privileged user to potentially enable denial of service via local access.
local
low complexity
intel CWE-190
4.4
2020-06-15 CVE-2020-0543 Incomplete Cleanup vulnerability in multiple products
Incomplete cleanup from specific special register read operations in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
5.5
2020-06-15 CVE-2020-0541 Out-of-bounds Write vulnerability in Intel Converged Security Management Engine Firmware
Out-of-bounds write in subsystem for Intel(R) CSME versions before 12.0.64, 13.0.32, 14.0.33 and 14.5.12 may allow a privileged user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-787
6.7
2020-06-15 CVE-2020-0539 Path Traversal vulnerability in Intel products
Path traversal in subsystem for Intel(R) DAL software for Intel(R) CSME versions before 11.8.77, 11.12.77, 11.22.77, 12.0.64, 13.0.32, 14.0.33 and Intel(R) TXE versions before 3.1.75, 4.0.25 may allow an unprivileged user to potentially enable denial of service via local access.
local
low complexity
intel CWE-22
5.5