CVE-2020-8761

MEDIUM

Intel(R) CSME <13.0.40,13.30.10 - Info Disclosure

Title source: llm
STIX 2.1

Description

Inadequate encryption strength in subsystem for Intel(R) CSME versions before 13.0.40 and 13.30.10 may allow an unauthenticated user to potentially enable information disclosure via physical access.

References (2)

Core 2
Core References
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20201113-0002/

Scores

CVSS v3 4.6
EPSS 0.0015
EPSS Percentile 4.8%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-326
Status published
Products (1)
intel/converged_security_and_manageability_engine < 13.0.40
Published Nov 12, 2020
Tracked Since Feb 18, 2026