CVE-2020-0590

HIGH

Intel Xeon Bronze/Silver/Gold Firmware - Authenticated Privilege Escalation via BIOS Input Validation

Title source: llm
STIX 2.1

Description

Improper input validation in BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via local access.

References (3)

Core 3
Core References
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20201113-0001/
Patch, Third Party Advisory x_refsource_confirm
https://cert-portal.siemens.com/productcert/pdf/ssa-678983.pdf

Scores

CVSS v3 7.8
EPSS 0.0035
EPSS Percentile 57.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-20
Status published
Products (50)
intel/xeon_bronze_3104_firmware
intel/xeon_bronze_3106_firmware
intel/xeon_bronze_3204_firmware
intel/xeon_bronze_3206r_firmware
intel/xeon_gold_5115_firmware
intel/xeon_gold_5118_firmware
intel/xeon_gold_5119t_firmware
intel/xeon_gold_5120_firmware
intel/xeon_gold_5120t_firmware
intel/xeon_gold_5122_firmware
... and 40 more
Published Nov 12, 2020
Tracked Since Feb 18, 2026