Vulnerability Name:

CVE-2020-24457

Assigned:2020-09-14
Published:2020-09-14
Updated:2020-09-22
Summary:Logic error in BIOS firmware for 8th, 9th and 10th Generation Intel(R) Core(TM) Processors may allow an unauthenticated user to potentially enable escalation of privilege, denial of service and/or information disclosure via physical access.
CVSS v3 Severity:7.6 High (CVSS v3.1 Vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Physical
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
7.6 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Physical
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
4.6 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-noinfo
References:Source: MITRE
Type: CNA
CVE-2020-24457

Source: MISC
Type: Vendor Advisory
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00347.html

Vulnerable Configuration:Configuration 1:
  • cpe:/o:intel:core_i7-8665ue_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:core_i7-8665ue:-:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/o:intel:core_i7-8665u_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:core_i7-8665u:-:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:intel:core_i7-8557u_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:core_i7-8557u:-:*:*:*:*:*:*:*

  • Configuration 4:
  • cpe:/o:intel:core_i7-8850h_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:core_i7-8850h:-:*:*:*:*:*:*:*

  • Configuration 5:
  • cpe:/o:intel:core_i7-8809g_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:core_i7-8809g:-:*:*:*:*:*:*:*

  • Configuration 6:
  • cpe:/o:intel:core_i7-8750h_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:core_i7-8750h:-:*:*:*:*:*:*:*

  • Configuration 7:
  • cpe:/o:intel:core_i7-8709g_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:core_i7-8709g:-:*:*:*:*:*:*:*

  • Configuration 8:
  • cpe:/o:intel:core_i7-8706g_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:core_i7-8706g:-:*:*:*:*:*:*:*

  • Configuration 9:
  • cpe:/o:intel:core_i7-8706g_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:core_i7-8706g:-:*:*:*:*:*:*:*

  • Configuration 10:
  • cpe:/o:intel:core_i7-8705g_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:core_i7-8705g:-:*:*:*:*:*:*:*

  • Configuration 11:
  • cpe:/o:intel:core_i7-8700t_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:core_i7-8700t:-:*:*:*:*:*:*:*

  • Configuration 12:
  • cpe:/o:intel:core_i7-8700k_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:core_i7-8700k:-:*:*:*:*:*:*:*

  • Configuration 13:
  • cpe:/o:intel:core_i7-8700b_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:core_i7-8700b:-:*:*:*:*:*:*:*

  • Configuration 14:
  • cpe:/o:intel:core_i7-8700_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:core_i7-8700:-:*:*:*:*:*:*:*

  • Configuration 15:
  • cpe:/o:intel:core_i7+8700_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:core_i7+8700:-:*:*:*:*:*:*:*

  • Configuration 16:
  • cpe:/o:intel:core_i7-8569u_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:core_i7-8569u:-:*:*:*:*:*:*:*

  • Configuration 17:
  • cpe:/o:intel:core_i7-8650u_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:core_i7-8650u:-:*:*:*:*:*:*:*

  • Configuration 18:
  • cpe:/o:intel:core_i7-8565u_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:core_i7-8565u:-:*:*:*:*:*:*:*

  • Configuration 19:
  • cpe:/o:intel:core_i7-8559u_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:core_i7-8559u:-:*:*:*:*:*:*:*

  • Configuration 20:
  • cpe:/o:intel:core_i7-8550u_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:core_i7-8550u:-:*:*:*:*:*:*:*

  • Configuration 21:
  • cpe:/o:intel:core_i7-8500y_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:core_i7-8500y:-:*:*:*:*:*:*:*

  • Configuration 22:
  • cpe:/o:intel:core_i7-8086k_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:core_i7-8086k:-:*:*:*:*:*:*:*

  • Configuration 23:
  • cpe:/o:intel:core_i9-9980hk_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:core_i9-9980hk:-:*:*:*:*:*:*:*

  • Configuration 24:
  • cpe:/o:intel:core_i9-9880h_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:core_i9-9880h:-:*:*:*:*:*:*:*

  • Configuration 25:
  • cpe:/o:intel:core_i9-9900t_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:core_i9-9900t:-:*:*:*:*:*:*:*

  • Configuration 26:
  • cpe:/o:intel:core_i9-9900ks_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:core_i9-9900ks:-:*:*:*:*:*:*:*

  • Configuration 27:
  • cpe:/o:intel:core_i9-9900kf_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:core_i9-9900kf:-:*:*:*:*:*:*:*

  • Configuration 28:
  • cpe:/o:intel:core_i9-9900k_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:core_i9-9900k:-:*:*:*:*:*:*:*

  • Configuration 29:
  • cpe:/o:intel:core_i9-9900_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:core_i9-9900:-:*:*:*:*:*:*:*

  • Configuration 30:
  • cpe:/o:intel:core_i7-10875h_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:core_i7-10875h:-:*:*:*:*:*:*:*

  • Configuration 31:
  • cpe:/o:intel:core_i7-10870h_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:core_i7-10870h:-:*:*:*:*:*:*:*

  • Configuration 32:
  • cpe:/o:intel:core_i7-10850h_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:core_i7-10850h:-:*:*:*:*:*:*:*

  • Configuration 33:
  • cpe:/o:intel:core_i7-10810u_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:core_i7-10810u:-:*:*:*:*:*:*:*

  • Configuration 34:
  • cpe:/o:intel:core_i7-10750h_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:core_i7-10750h:-:*:*:*:*:*:*:*

  • Configuration 35:
  • cpe:/o:intel:core_i7-10710u_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:core_i7-10710u:-:*:*:*:*:*:*:*

  • Configuration 36:
  • cpe:/o:intel:core_i7-10700te_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:core_i7-10700te:-:*:*:*:*:*:*:*

  • Configuration 37:
  • cpe:/o:intel:core_i7-10700t_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:core_i7-10700t:-:*:*:*:*:*:*:*

  • Configuration 38:
  • cpe:/o:intel:core_i7-10700kf_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:core_i7-10700kf:-:*:*:*:*:*:*:*

  • Configuration 39:
  • cpe:/o:intel:core_i7-10700k_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:core_i7-10700k:-:*:*:*:*:*:*:*

  • Configuration 40:
  • cpe:/o:intel:core_i7-10700f_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:core_i7-10700f:-:*:*:*:*:*:*:*

  • Configuration 41:
  • cpe:/o:intel:core_i7-10700e_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:core_i7-10700e:-:*:*:*:*:*:*:*

  • Configuration 42:
  • cpe:/o:intel:core_i7-10700_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:core_i7-10700:-:*:*:*:*:*:*:*

  • Configuration 43:
  • cpe:/o:intel:core_i7-1065g7_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:core_i7-1065g7:-:*:*:*:*:*:*:*

  • Configuration 44:
  • cpe:/o:intel:core_i7-10610u_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:core_i7-10610u:-:*:*:*:*:*:*:*

  • Configuration 45:
  • cpe:/o:intel:core_i7-1060g7_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:core_i7-1060g7:-:*:*:*:*:*:*:*

  • Configuration 46:
  • cpe:/o:intel:core_i7-1068ng7_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:core_i7-1068ng7:-:*:*:*:*:*:*:*

  • Configuration 47:
  • cpe:/o:intel:core_i7-10510u_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:core_i7-10510u:-:*:*:*:*:*:*:*

  • Configuration 48:
  • cpe:/o:intel:core_i7-10510y_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:core_i7-10510y:-:*:*:*:*:*:*:*

  • Configuration 49:
  • cpe:/o:intel:pentium_silver_n5000_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:pentium_silver_n5000:-:*:*:*:*:*:*:*

  • Configuration 50:
  • cpe:/o:intel:pentium_silver_j5040_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:pentium_silver_j5040:-:*:*:*:*:*:*:*

  • Configuration 51:
  • cpe:/o:intel:pentium_silver_j5005_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:pentium_silver_j5005:-:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Vulnerability Name:

    CVE-2020-24457 (CCN-188262)

    Assigned:2020-09-08
    Published:2020-09-08
    Updated:2020-09-22
    Summary:Logic error in BIOS firmware for 8th, 9th and 10th Generation Intel(R) Core(TM) Processors may allow an unauthenticated user to potentially enable escalation of privilege, denial of service and/or information disclosure via physical access.
    CVSS v3 Severity:7.6 High (CVSS v3.1 Vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
    6.6 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C)
    Exploitability Metrics:Attack Vector (AV): Physical
    Attack Complexity (AC): Low
    Privileges Required (PR): None
    User Interaction (UI): None
    Scope:Scope (S): Changed
    Impact Metrics:Confidentiality (C): High
    Integrity (I): High
    Availibility (A): High
    7.6 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
    6.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C)
    Exploitability Metrics:Attack Vector (AV): Physical
    Attack Complexity (AC): Low
    Privileges Required (PR): None
    User Interaction (UI): None
    Scope:Scope (S): Changed
    Impact Metrics:Confidentiality (C): High
    Integrity (I): High
    Availibility (A): High
    CVSS v2 Severity:4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
    Exploitability Metrics:Access Vector (AV): Local
    Access Complexity (AC): Low
    Authentication (Au): None
    Impact Metrics:Confidentiality (C): Partial
    Integrity (I): Partial
    Availibility (A): Partial
    7.2 High (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
    Exploitability Metrics:Access Vector (AV): Local
    Access Complexity (AC): Low
    Athentication (Au): None
    Impact Metrics:Confidentiality (C): Complete
    Integrity (I): Complete
    Availibility (A): Complete
    Vulnerability Type:CWE-noinfo
    Vulnerability Consequences:Gain Privileges
    References:Source: MITRE
    Type: CNA
    CVE-2020-24457

    Source: XF
    Type: UNKNOWN
    intel-cve202024457-priv-esc(188262)

    Source: CCN
    Type: INTEL-SA-00347
    Intel BIOS Advisory

    Source: MISC
    Type: Vendor Advisory
    https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00347.html

    BACK
    intel core i7-8665ue firmware -
    intel core i7-8665ue -
    intel core i7-8665u firmware -
    intel core i7-8665u -
    intel core i7-8557u firmware -
    intel core i7-8557u -
    intel core i7-8850h firmware -
    intel core i7-8850h -
    intel core i7-8809g firmware -
    intel core i7-8809g -
    intel core i7-8750h firmware -
    intel core i7-8750h -
    intel core i7-8709g firmware -
    intel core i7-8709g -
    intel core i7-8706g firmware -
    intel core i7-8706g -
    intel core i7-8706g firmware -
    intel core i7-8706g -
    intel core i7-8705g firmware -
    intel core i7-8705g -
    intel core i7-8700t firmware -
    intel core i7-8700t -
    intel core i7-8700k firmware -
    intel core i7-8700k -
    intel core i7-8700b firmware -
    intel core i7-8700b -
    intel core i7-8700 firmware -
    intel core i7-8700 -
    intel core i7+8700 firmware -
    intel core i7+8700 -
    intel core i7-8569u firmware -
    intel core i7-8569u -
    intel core i7-8650u firmware -
    intel core i7-8650u -
    intel core i7-8565u firmware -
    intel core i7-8565u -
    intel core i7-8559u firmware -
    intel core i7-8559u -
    intel core i7-8550u firmware -
    intel core i7-8550u -
    intel core i7-8500y firmware -
    intel core i7-8500y -
    intel core i7-8086k firmware -
    intel core i7-8086k -
    intel core i9-9980hk firmware -
    intel core i9-9980hk -
    intel core i9-9880h firmware -
    intel core i9-9880h -
    intel core i9-9900t firmware -
    intel core i9-9900t -
    intel core i9-9900ks firmware -
    intel core i9-9900ks -
    intel core i9-9900kf firmware -
    intel core i9-9900kf -
    intel core i9-9900k firmware -
    intel core i9-9900k -
    intel core i9-9900 firmware -
    intel core i9-9900 -
    intel core i7-10875h firmware -
    intel core i7-10875h -
    intel core i7-10870h firmware -
    intel core i7-10870h -
    intel core i7-10850h firmware -
    intel core i7-10850h -
    intel core i7-10810u firmware -
    intel core i7-10810u -
    intel core i7-10750h firmware -
    intel core i7-10750h -
    intel core i7-10710u firmware -
    intel core i7-10710u -
    intel core i7-10700te firmware -
    intel core i7-10700te -
    intel core i7-10700t firmware -
    intel core i7-10700t -
    intel core i7-10700kf firmware -
    intel core i7-10700kf -
    intel core i7-10700k firmware -
    intel core i7-10700k -
    intel core i7-10700f firmware -
    intel core i7-10700f -
    intel core i7-10700e firmware -
    intel core i7-10700e -
    intel core i7-10700 firmware -
    intel core i7-10700 -
    intel core i7-1065g7 firmware -
    intel core i7-1065g7 -
    intel core i7-10610u firmware -
    intel core i7-10610u -
    intel core i7-1060g7 firmware -
    intel core i7-1060g7 -
    intel core i7-1068ng7 firmware -
    intel core i7-1068ng7 -
    intel core i7-10510u firmware -
    intel core i7-10510u -
    intel core i7-10510y firmware -
    intel core i7-10510y -
    intel pentium silver n5000 firmware -
    intel pentium silver n5000 -
    intel pentium silver j5040 firmware -
    intel pentium silver j5040 -
    intel pentium silver j5005 firmware -
    intel pentium silver j5005 -