CVE-2020-8707

CVSS V2 Medium 5.8 CVSS V3 High 8.8
Description
Buffer overflow in daemon for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.
Overview
  • CVE ID
  • CVE-2020-8707
  • Assigner
  • secure@intel.com
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2020-08-13T03:15:15
  • Last Modified Date
  • 2020-08-19T17:11:42
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
AND
cpe:2.3:o:intel:server_board_s2600wt_firmware:*:*:*:*:*:*:*:* 1 OR 1.59
cpe:2.3:h:intel:server_board_s2600wt2:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_board_s2600wt2r:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_board_s2600wtt:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_board_s2600wttr:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:intel:server_system_r1000wt_firmware:*:*:*:*:*:*:*:* 1 OR 1.59
cpe:2.3:h:intel:server_system_r1208wt2gs:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_r1208wt2gsr:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_r1208wttgs:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_r1208wttgsbpp:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_r1208wttgsr:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_r1304wt2gs:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_r1304wt2gsr:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_r1304wttgs:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_r1304wttgsr:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:intel:server_system_r2000wt_firmware:*:*:*:*:*:*:*:* 1 OR 1.59
cpe:2.3:h:intel:server_system_r2208wt2ys:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_r2208wt2ysr:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_r2208wttyc1:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_r2208wttyc1r:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_r2208wttys:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_r2208wttysr:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_r2224wttys:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_r2224wttysr:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_r2308wttys:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_r2308wttysr:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_r2312wttys:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_r2312wttysr:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:intel:server_board_s2600cw:*:*:*:*:*:*:*:* 1 OR 1.59
cpe:2.3:a:intel:server_board_s2600cw2:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:a:intel:server_board_s2600cw2r:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:a:intel:server_board_s2600cw2s:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:a:intel:server_board_s2600cw2sr:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:a:intel:server_board_s2600cwt:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:a:intel:server_board_s2600cwtr:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:a:intel:server_board_s2600cwts:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:a:intel:server_board_s2600cwtsr:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:intel:compute_module_hns2600kp_firmware:*:*:*:*:*:*:*:* 1 OR 1.59
cpe:2.3:h:intel:compute_module_hns2600kp:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:compute_module_hns2600kpf:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:compute_module_hns2600kpfr:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:compute_module_hns2600kpr:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:intel:server_board_s2600kp_firmware:*:*:*:*:*:*:*:* 1 OR 1.59
cpe:2.3:h:intel:server_board_s2600kp:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_board_s2600kpf:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_board_s2600kpfr:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_board_s2600kpr:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_board_s2600kptr:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:intel:compute_module_hns2600tp_firmware:*:*:*:*:*:*:*:* 1 OR 1.59
cpe:2.3:h:intel:compute_module_hns2600tp:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:compute_module_hns2600tp24r:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:compute_module_hns2600tp24sr:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:compute_module_hns2600tpf:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:compute_module_hns2600tpfr:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:compute_module_hns2600tpr:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:intel:compute_module_s2600tp_firmware:*:*:*:*:*:*:*:* 1 OR 1.59
cpe:2.3:h:intel:server_board_s2600tp:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_board_s2600tpf:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_board_s2600tpfr:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_board_s2600tpr:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:intel:server_board_s1200sp_firmware:*:*:*:*:*:*:*:* 1 OR 1.59
cpe:2.3:h:intel:server_board_s1200spl:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_board_s1200splr:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_board_s1200spo:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_board_s1200spor:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_board_s1200sps:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_board_s1200spsr:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:intel:server_system_lr1304sp_firmware:*:*:*:*:*:*:*:* 1 OR 1.59
cpe:2.3:h:intel:server_system_lr1304spcfg1:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_lr1304spcfg1r:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_lr1304spcfsgx1:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:intel:server_system_lsvrp_firmware:*:*:*:*:*:*:*:* 1 OR 1.59
cpe:2.3:h:intel:server_system_lsvrp4304es6xx1:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_lsvrp4304es6xxr:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:intel:server_system_r1000sp_firmware:*:*:*:*:*:*:*:* 1 OR 1.59
cpe:2.3:h:intel:server_system_r1208sposhor:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_r1208sposhorr:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_r1304sposhbn:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_r1304sposhbnr:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_r1304sposhor:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_r1304sposhorr:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:intel:server_board_s2600wf_firmware:*:*:*:*:*:*:*:* 1 OR 1.59
cpe:2.3:h:intel:server_board_s2600wf0:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_board_s2600wf0r:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_board_s2600wfq:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_board_s2600wfqr:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_board_s2600wft:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_board_s2600wftr:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:intel:server_system_r1000wf_firmware:*:*:*:*:*:*:*:* 1 OR 1.59
cpe:2.3:h:intel:server_system_lnetcnt3y:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_mcb2208wfaf4:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_mcb2208wfaf5:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_mcb2208wfaf6:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_mcb2208wfhy2:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_nb2208wfqnfvi:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_r1208wfqysr:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_r1208wftys:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_r1208wftysr:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_r1304wf0ys:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_r1304wf0ysr:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_r1304wftys:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_r1304wftysr:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:intel:server_system_r2000wf_firmware:*:*:*:*:*:*:*:* 1 OR 1.59
cpe:2.3:h:intel:server_system_r2208wf0zs:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_r2208wf0zsr:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_r2208wfqzs:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_r2208wfqzsr:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_r2208wftzs:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_r2208wftzsr:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_r2224wfqzs:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_r2224wftzs:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_r2224wftzsr:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_r2308wftzs:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_r2308wftzsr:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_r2312wf0np:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_r2312wf0npr:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_r2312wfqzs:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_r2312wftzs:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_r2312wftzsr:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_vrn2208waf6:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_vrn2208wfaf81:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_vrn2208wfaf82:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_vrn2208wfaf83:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_system_vrn2208wfhy6:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:intel:server_board_s2600st_firmware:*:*:*:*:*:*:*:* 1 OR 1.59
cpe:2.3:h:intel:server_board_s2600stb:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_board_s2600stbr:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_board_s2600stq:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_board_s2600stqr:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:intel:compute_module_hns2600bp_firmware:*:*:*:*:*:*:*:* 1 OR 1.59
cpe:2.3:h:intel:compute_module_hns2600bpb:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:compute_module_hns2600bpb24:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:compute_module_hns2600bpb24r:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:compute_module_hns2600bpblc:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:compute_module_hns2600bpblc24:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:compute_module_hns2600bpblc24r:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:compute_module_hns2600bpblcr:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:compute_module_hns2600bpbr:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:compute_module_hns2600bpq:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:compute_module_hns2600bpq24:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:compute_module_hns2600bpq24r:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:compute_module_hns2600bpqr:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:compute_module_hns2600bps:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:compute_module_hns2600bps24:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:compute_module_hns2600bps24r:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:compute_module_hns2600bpsr:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:intel:server_board_s2600bp_firmware:*:*:*:*:*:*:*:* 1 OR 1.59
cpe:2.3:h:intel:server_board_s2600bpb:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_board_s2600bpbr:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_board_s2600bpq:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_board_s2600bpqr:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_board_s2600bps:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:h:intel:server_board_s2600bpsr:-:*:*:*:*:*:*:* 0 OR
CVSS Version 2
  • Version
  • 2.0
  • Vector String
  • AV:A/AC:L/Au:N/C:P/I:P/A:P
  • Access Vector
  • ADJACENT_NETWORK
  • Access Compatibility
  • LOW
  • Authentication
  • NONE
  • Confidentiality Impact
  • PARTIAL
  • Integrity Impact
  • PARTIAL
  • Availability Impact
  • PARTIAL
  • Base Score
  • 5.8
  • Severity
  • MEDIUM
  • Exploitability Score
  • 6.5
  • Impact Score
  • 6.4
CVSS Version 3
  • Version
  • 3.1
  • Vector String
  • CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Attack Vector
  • ADJACENT_NETWORK
  • Attack Compatibility
  • LOW
  • Privileges Required
  • NONE
  • User Interaction
  • NONE
  • Scope
  • UNCHANGED
  • Confidentiality Impact
  • HIGH
  • Availability Impact
  • HIGH
  • Base Score
  • 8.8
  • Base Severity
  • HIGH
  • Exploitability Score
  • 2.8
  • Impact Score
  • 5.9
History
Created Old Value New Value Data Type Notes
2022-05-10 17:19:51 Added to TrackCVE
2022-12-04 20:56:35 2020-08-13T03:15Z 2020-08-13T03:15:15 CVE Published Date updated
2022-12-04 20:56:35 2020-08-19T17:11:42 CVE Modified Date updated
2022-12-04 20:56:35 Analyzed Vulnerability Status updated