CVE-2020-12360

HIGH

Intel Bios - Out-of-Bounds Read

Title source: rule
STIX 2.1

Description

Out of bounds read in the firmware for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via local access.

References (3)

Core 3
Core References
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20210702-0002/
Patch, Third Party Advisory x_refsource_confirm
https://cert-portal.siemens.com/productcert/pdf/ssa-309571.pdf

Scores

CVSS v3 7.8
EPSS 0.0037
EPSS Percentile 59.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-125
Status published
Products (11)
intel/bios
netapp/aff_bios
netapp/cloud_backup
netapp/e-series_bios
netapp/fas_bios
netapp/hci_compute_node_bios
netapp/hci_storage_node_bios
netapp/solidfire_bios
siemens/simatic_cpu_1518-4_firmware
siemens/simatic_cpu_1518f-4_firmware
... and 1 more
Published Jun 09, 2021
Tracked Since Feb 18, 2026