CVE-2020-24486

MEDIUM

Intel BIOS - Authenticated Denial of Service via Improper Input Validation

Title source: llm
STIX 2.1

Description

Improper input validation in the firmware for some Intel(R) Processors may allow an authenticated user to potentially enable denial of service via local access.

References (3)

Core 3
Core References
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20210702-0002/
Patch, Third Party Advisory x_refsource_confirm
https://cert-portal.siemens.com/productcert/pdf/ssa-309571.pdf

Scores

CVSS v3 5.5
EPSS 0.0025
EPSS Percentile 47.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-20
Status published
Products (9)
intel/bios
netapp/aff_bios
netapp/cloud_backup
netapp/e-series_bios
netapp/fas_bios
netapp/hci_compute_node_bios
netapp/hci_storage_node_bios
netapp/solidfire_bios
siemens/simatic_ipc547g_firmware
Published Jun 09, 2021
Tracked Since Feb 18, 2026