CERT-In Advisory
CIAD-2020-0078
Multiple Vulnerabilities in Intel Products
Original Issue Date: November 17, 2020
Severity Rating: High
Systems Affected
- 2nd Generation Intel® Xeon® Scalable and Intel® Xeon® Scalable Processors
- Intel® Xeon® Processor D Family
- 10th Generation Intel® Core¿ processors
- 9th Generation Intel® Core¿ processors
- 8th Generation Intel® Core¿ processors
- 7th Generation Intel® Core¿ processors
- 6th Generation Intel® Core¿ processors
- Intel® Core¿ Processors with Intel® Hybrid Technology
- Intel® Xeon® Processor E7 v4 Family and Intel® Xeon® Processor E7 v2 Family
- Intel® Core¿ X-series Processors and Intel® Xeon® Processor W Family
- Intel® Xeon® Processor D Family, Intel® Xeon® W Processor and Intel® Core¿ X-series Processors
Overview
Multiple Vulnerabilities has been reported in Intel BIOS firmware which could allow the remote attacker to enable escalation of privilege and cause denial of Service on a targeted system.
Description
These vulnerabilities exists Intel BIOS firmware due to improper input validation, improper conditions check, improper buffer restrictions and out of bounds write. A remote attacker could exploit these vulnerabilities by local access resulting in potentially enable escalation of privilege and/or denial of service.
Successful exploitation of these vulnerabilities could allow the attacker to potentially enable escalation of privilege and cause denial of service on the targeted system.
Solution
Apply appropriate updates as mentioned in:
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00358.html
Vendor Information
Intel
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00358.html
References
Intel
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00358.html
CVE Name
CVE-2020-0590
CVE-2020-0587
CVE-2020-0591
CVE-2020-0593
CVE-2020-0588
CVE-2020-0592
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|