Vulnerability Details CVE-2020-8744
Improper initialization in subsystem for Intel(R) CSME versions before12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE versions before 4.0.30 Intel(R) SPS versions before E3_05.01.04.200 may allow a privileged user to potentially enable escalation of privilege via local access.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 42.1%
CVSS Severity
CVSS v3 Score 7.8
CVSS v2 Score 4.6
Products affected by CVE-2020-8744
-
cpe:2.3:a:intel:converged_security_and_management_engine:11.11.0
-
cpe:2.3:a:intel:converged_security_and_management_engine:11.11.65
-
cpe:2.3:a:intel:converged_security_and_management_engine:11.22.0
-
cpe:2.3:a:intel:converged_security_and_management_engine:11.22.65
-
cpe:2.3:a:intel:converged_security_and_management_engine:11.8.0
-
cpe:2.3:a:intel:converged_security_and_management_engine:11.8.65
-
cpe:2.3:a:intel:converged_security_and_management_engine:12.0
-
cpe:2.3:a:intel:converged_security_and_management_engine:12.0.35
-
cpe:2.3:a:intel:converged_security_and_management_engine:13.0.0
-
cpe:2.3:a:intel:converged_security_and_management_engine:13.30.0
-
cpe:2.3:a:intel:converged_security_and_management_engine:14.0.0
-
cpe:2.3:a:intel:converged_security_and_management_engine:14.5.0
-
cpe:2.3:a:intel:server_platform_services:*
-
cpe:2.3:h:siemens:simatic_s7-1500:-
-
cpe:2.3:h:siemens:simatic_s7-1518-4_pn/dp_mfp:-
-
cpe:2.3:h:siemens:simatic_s7-1518f-4_pn/dp_mfp:-
-
cpe:2.3:o:intel:trusted_execution_engine:3.0
-
cpe:2.3:o:intel:trusted_execution_engine:3.1.75
-
cpe:2.3:o:intel:trusted_execution_engine:3.1.80
-
cpe:2.3:o:intel:trusted_execution_engine:4.0.25
-
cpe:2.3:o:siemens:simatic_s7-1500_firmware:-
-
cpe:2.3:o:siemens:simatic_s7-1518-4_pn/dp_mfp_firmware:-
-
cpe:2.3:o:siemens:simatic_s7-1518f-4_pn/dp_mfp_firmware:-