Vulnerability Name:
CVE-2020-0555 (CCN-186533)
Assigned:
2019-10-28
Published:
2020-08-11
Updated:
2020-08-19
Summary:
Improper input validation for some Intel(R) Wireless Bluetooth(R) products may allow an authenticated user to potentially enable escalation of privilege via local access.
CVSS v3 Severity:
7.8 High
(CVSS v3.1 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
)
6.8 Medium
(Temporal CVSS v3.1 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
)
Exploitability Metrics:
Attack Vector (AV):
Local
Attack Complexity (AC):
Low
Privileges Required (PR):
Low
User Interaction (UI):
None
Scope:
Scope (S):
Unchanged
Impact Metrics:
Confidentiality (C):
High
Integrity (I):
High
Availibility (A):
High
8.4 High
(CCN CVSS v3.1 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
)
7.3 High
(CCN Temporal CVSS v3.1 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C
)
Exploitability Metrics:
Attack Vector (AV):
Local
Attack Complexity (AC):
Low
Privileges Required (PR):
Low
User Interaction (UI):
None
Scope:
Scope (S):
Changed
Impact Metrics:
Confidentiality (C):
High
Integrity (I):
High
Availibility (A):
None
CVSS v2 Severity:
4.6 Medium
(CVSS v2 Vector:
AV:L/AC:L/Au:N/C:P/I:P/A:P
)
Exploitability Metrics:
Access Vector (AV):
Local
Access Complexity (AC):
Low
Authentication (Au):
None
Impact Metrics:
Confidentiality (C):
Partial
Integrity (I):
Partial
Availibility (A):
Partial
6.2 Medium
(CCN CVSS v2 Vector:
AV:L/AC:L/Au:S/C:C/I:C/A:N
)
Exploitability Metrics:
Access Vector (AV):
Local
Access Complexity (AC):
Low
Athentication (Au):
Single_Instance
Impact Metrics:
Confidentiality (C):
Complete
Integrity (I):
Complete
Availibility (A):
None
Vulnerability Type:
CWE-20
Vulnerability Consequences:
Gain Privileges
References:
Source: MITRE
Type: CNA
CVE-2020-0555
Source: XF
Type: UNKNOWN
intel-cve20200555-priv-esc(186533)
Source: CCN
Type: INTEL-SA-00337
Intel Wireless Bluetooth Advisory
Source: MISC
Type: Patch, Vendor Advisory
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00337.html
Vulnerable Configuration:
Configuration 1
:
cpe:/o:intel:ax201_firmware:-:*:*:*:*:*:*:*
AND
cpe:/h:intel:ax201:-:*:*:*:*:*:*:*
Configuration 2
:
cpe:/o:intel:ax200_firmware:-:*:*:*:*:*:*:*
AND
cpe:/h:intel:ax200:-:*:*:*:*:*:*:*
Configuration 3
:
cpe:/o:intel:ac_9560_firmware:-:*:*:*:*:*:*:*
AND
cpe:/h:intel:ac_9560:-:*:*:*:*:*:*:*
Configuration 4
:
cpe:/o:intel:ac_9462_firmware:-:*:*:*:*:*:*:*
AND
cpe:/h:intel:ac_9462:-:*:*:*:*:*:*:*
Configuration 5
:
cpe:/o:intel:ac_9461_firmware:-:*:*:*:*:*:*:*
AND
cpe:/h:intel:ac_9461:-:*:*:*:*:*:*:*
Configuration 6
:
cpe:/o:intel:ac_9260_firmware:-:*:*:*:*:*:*:*
AND
cpe:/h:intel:ac_9260:-:*:*:*:*:*:*:*
Configuration 7
:
cpe:/o:intel:ac_8265_firmware:-:*:*:*:*:*:*:*
AND
cpe:/h:intel:ac_8265:-:*:*:*:*:*:*:*
Configuration 8
:
cpe:/o:intel:ac_8260_firmware:-:*:*:*:*:*:*:*
AND
cpe:/h:intel:ac_8260:-:*:*:*:*:*:*:*
Configuration 9
:
cpe:/o:intel:ac_3168_firmware:-:*:*:*:*:*:*:*
AND
cpe:/h:intel:ac_3168:-:*:*:*:*:*:*:*
Configuration 10
:
cpe:/o:intel:ac_7265_firmware:-:*:*:*:*:*:*:*
AND
cpe:/h:intel:ac_7265:-:*:*:*:*:*:*:*
Configuration 11
:
cpe:/o:intel:ac_3165_firmware:-:*:*:*:*:*:*:*
AND
cpe:/h:intel:ac_3165:-:*:*:*:*:*:*:*
Configuration CCN 1
:
cpe:/h:intel:wi-fi_6_ax201:-:*:*:*:*:*:*:*
OR
cpe:/h:intel:wi-fi_6_ax200:-:*:*:*:*:*:*:*
OR
cpe:/h:intel:wireless-ac_9560:-:*:*:*:*:*:*:*
OR
cpe:/h:intel:wireless-ac_9462:-:*:*:*:*:*:*:*
OR
cpe:/h:intel:wireless-ac_9461:-:*:*:*:*:*:*:*
OR
cpe:/h:intel:wireless-ac_9260:-:*:*:*:*:*:*:*
OR
cpe:/h:intel:dual_band_wireless-ac_8265:-:*:*:*:*:*:*:*
OR
cpe:/h:intel:dual_band_wireless-ac_8260:-:*:*:*:*:*:*:*
OR
cpe:/h:intel:dual_band_wireless-ac_3168:-:*:*:*:*:*:*:*
OR
cpe:/h:intel:dual_band_wireless-ac_3165:-:*:*:*:*:*:*:*
Denotes that component is vulnerable
BACK
intel
ax201 firmware -
intel
ax201 -
intel
ax200 firmware -
intel
ax200 -
intel
ac 9560 firmware -
intel
ac 9560 -
intel
ac 9462 firmware -
intel
ac 9462 -
intel
ac 9461 firmware -
intel
ac 9461 -
intel
ac 9260 firmware -
intel
ac 9260 -
intel
ac 8265 firmware -
intel
ac 8265 -
intel
ac 8260 firmware -
intel
ac 8260 -
intel
ac 3168 firmware -
intel
ac 3168 -
intel
ac 7265 firmware -
intel
ac 7265 -
intel
ac 3165 firmware -
intel
ac 3165 -
intel
wi-fi 6 ax201 -
intel
wi-fi 6 ax200 -
intel
wireless-ac 9560 -
intel
wireless-ac 9462 -
intel
wireless-ac 9461 -
intel
wireless-ac 9260 -
intel
dual band wireless-ac 8265 -
intel
dual band wireless-ac 8260 -
intel
dual band wireless-ac 3168 -
intel
dual band wireless-ac 3165 -