VYPR
Medium severity6.8NVD Advisory· Published Nov 12, 2020· Updated Jun 17, 2026

CVE-2020-8705

CVE-2020-8705

Description

Insecure default initialization of resource in Intel(R) Boot Guard in Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE versions before 3.1.80 and 4.0.30, Intel(R) SPS versions before E5_04.01.04.400, E3_04.01.04.200, SoC-X_04.00.04.200 and SoC-A_04.00.04.300 may allow an unauthenticated user to potentially enable escalation of privileges via physical access.

Affected products

12
  • cpe:2.3:a:intel:converged_security_and_manageability_engine:*:*:*:*:*:*:*:*
    Range: <11.8.80
  • cpe:2.3:a:intel:server_platform_services:sps_e3_04.01.04.200:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:intel:server_platform_services:sps_e3_04.01.04.200:*:*:*:*:*:*:*
    • cpe:2.3:a:intel:server_platform_services:sps_e5_04.01.04.400:*:*:*:*:*:*:*
    • cpe:2.3:a:intel:server_platform_services:sps_soc-a_04.00.04.300:*:*:*:*:*:*:*
    • cpe:2.3:a:intel:server_platform_services:sps_soc-x_04.00.04.200:*:*:*:*:*:*:*
  • cpe:2.3:a:intel:trusted_execution_technology:3.1.80:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:intel:trusted_execution_technology:3.1.80:*:*:*:*:*:*:*
    • cpe:2.3:a:intel:trusted_execution_technology:4.0.30:*:*:*:*:*:*:*
  • Intel(R)/CSMEdescription
  • Intel/Boot Guardllm-fuzzy
  • Intel/TXEllm-fuzzy
    Range: <3.1.80, <4.0.30
  • Intel/CSMEllm-fuzzy
    Range: <11.8.80, <11.12.80, <11.22.80, <12.0.70, <13.0.40, <13.30.10, <14.0.45, <14.5.25
  • Intel/SPSllm-fuzzy
    Range: <E5_04.01.04.400, <E3_04.01.04.200, <SoC-X_04.00.04.200, <SoC-A_04.00.04.300

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.