Versio.io

CVE-2020-5955

Common vulnerabilities & exposures (CVE)

CVE databaseCVE database blogpostRelease & EoL database
 
Published at: - 03-11-2021 02:15
Last modified: - 12-04-2022 08:05
Total changes: - 2

Description

An issue was discovered in Int15MicrocodeSmm in Insyde InsydeH2O before 2021-10-14 on Intel client chipsets. A caller may be able to escalate privileges.

Common Vulnerability Scoring System (CVSS)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Low
Attack complexity
Network
Attack vector
High
Availability
High
Confidentiality
High
Integrity
None
Privileges required
Unchanged
Scope
None
User interaction
9.8
Base score
3.9
5.9
Exploitability score
Impact score
 

Verification logic

OR
AND
OR
vendor=insyde AND product=insydeh2o_uefi_bios AND versionEndExcluding=05.32.30.0001
OR
vendor=intel AND product=ice_lake AND version=-
AND
OR
vendor=insyde AND product=insydeh2o_uefi_bios AND versionEndExcluding=05.41.35.0001
OR
vendor=intel AND product=tiger_lake AND version=-
AND
OR
vendor=insyde AND product=insydeh2o_uefi_bios AND versionEndExcluding=05.42.11.0026
OR
vendor=intel AND product=whitley-sp AND version=-
AND
OR
vendor=insyde AND product=insydeh2o_uefi_bios AND versionEndExcluding=05.04.21.0068
OR
vendor=intel AND product=grantley-ep AND version=-
AND
OR
vendor=insyde AND product=insydeh2o_uefi_bios AND versionEndExcluding=05.42.09.0003
OR
vendor=intel AND product=elkhart_lake AND version=-
AND
OR
vendor=insyde AND product=insydeh2o_uefi_bios AND versionEndExcluding=05.21.51.0040
OR
vendor=intel AND product=purley-ep_refresh_neon_city AND version=-
AND
OR
vendor=insyde AND product=insydeh2o_uefi_bios AND versionEndExcluding=05.34.09.0030
OR
vendor=intel AND product=comet_lake_rvp AND version=- AND software_edition=embedded
AND
OR
vendor=insyde AND product=insydeh2o_uefi_bios AND versionEndExcluding=05.34.09.0030
OR
vendor=intel AND product=comet_lake_rvp AND version=- AND software_edition=server
AND
OR
vendor=insyde AND product=insydeh2o_uefi_bios AND versionEndExcluding=05.32.47.0001
OR
vendor=intel AND product=comet_lake AND version=- AND software_edition=client
AND
OR
vendor=insyde AND product=insydeh2o_uefi_bios AND versionEndExcluding=05.23.45.0023
OR
vendor=intel AND product=whiskey_lake_rvp AND version=- AND software_edition=embedded
AND
OR
vendor=insyde AND product=insydeh2o_uefi_bios AND versionEndExcluding=05.23.45.0023
OR
vendor=intel AND product=whiskey_lake_rvp AND version=- AND software_edition=server
AND
OR
vendor=insyde AND product=insydeh2o_uefi_bios AND versionEndExcluding=05.21.43.0001
OR
vendor=intel AND product=whiskey_lake AND version=- AND software_edition=client
AND
OR
vendor=insyde AND product=insydeh2o_uefi_bios AND versionEndExcluding=05.23.04.0045
OR
vendor=intel AND product=mehlow AND version=- AND software_edition=embedded
AND
OR
vendor=insyde AND product=insydeh2o_uefi_bios AND versionEndExcluding=05.23.04.0045
OR
vendor=intel AND product=mehlow-r AND version=- AND software_edition=embedded
AND
OR
vendor=insyde AND product=insydeh2o_uefi_bios AND versionEndExcluding=05.23.04.0045
OR
vendor=intel AND product=mehlow-r AND version=- AND software_edition=server
AND
OR
vendor=insyde AND product=insydeh2o_uefi_bios AND versionEndExcluding=05.23.04.0045
OR
vendor=intel AND product=mehlow AND version=- AND software_edition=server
AND
OR
vendor=insyde AND product=insydeh2o_uefi_bios AND versionEndExcluding=05.21.43.0001
OR
vendor=intel AND product=coffee_lake AND version=- AND software_edition=client
AND
OR
vendor=insyde AND product=insydeh2o_uefi_bios AND versionEndExcluding=05.21.43.0001
OR
vendor=intel AND product=cannon_lake AND version=-
AND
OR
vendor=insyde AND product=insydeh2o_uefi_bios AND versionEndExcluding=05.11.26.0015
OR
vendor=intel AND product=kaby_lake_mrd AND version=-
AND
OR
vendor=insyde AND product=insydeh2o_uefi_bios AND versionEndExcluding=05.12.09.0075
OR
vendor=intel AND product=greenlow AND version=- AND software_edition=embedded
AND
OR
vendor=insyde AND product=insydeh2o_uefi_bios AND versionEndExcluding=05.12.09.0075
OR
vendor=intel AND product=greenlow-r AND version=-
AND
OR
vendor=insyde AND product=insydeh2o_uefi_bios AND versionEndExcluding=05.12.09.0075
OR
vendor=intel AND product=greenlow AND version=- AND software_edition=server
AND
OR
vendor=insyde AND product=insydeh2o_uefi_bios AND versionEndExcluding=05.12.09.0075
OR
vendor=intel AND product=greenlow-r AND version=- AND software_edition=embedded
AND
OR
vendor=insyde AND product=insydeh2o_uefi_bios AND versionEndExcluding=05.10.48.0001
OR
vendor=intel AND product=kaby_lake AND version=- AND software_edition=client
AND
OR
vendor=insyde AND product=insydeh2o_uefi_bios AND versionEndExcluding=05.05.39.0001
OR
vendor=intel AND product=skylake_mrd AND version=-
AND
OR
vendor=insyde AND product=insydeh2o_uefi_bios AND versionEndExcluding=05.04.15.0001
OR
vendor=intel AND product=skylake AND version=-
AND
OR
vendor=insyde AND product=insydeh2o_uefi_bios AND versionEndExcluding=05.23.27.0001
OR
vendor=intel AND product=coffee_lake AND version=-
AND
OR
vendor=insyde AND product=insydeh2o_uefi_bios AND versionEndExcluding=05.23.27.0001
OR
vendor=intel AND product=whiskey_lake AND version=-
 

Reference

 


Keywords

NVD

 

CVE-2020-5955

 

CVE

 

Common vulnerabilities & exposures

 

CVSS

 

Common vulnerability scoring system

 

Security

 

Vulnerabilities

 

Exposures

 

We use cookies to ensure that we give you the best experience on our website. Read privacy policies for more information.