CVE-2020-8704

Race condition in a subsystem in the Intel(R) LMS versions before 2039.1.0.0 may allow a privileged user to potentially enable escalation of privilege via local access.
Race Condition
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.4 MEDIUM
LOCAL
HIGH
HIGH
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
intelCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 31%
VendorProductVersion
intellocal_manageability_service
𝑥
< 2039.1.0.0
siemenssimatic_field_pg_m5_firmware
*
siemenssimatic_field_pg_m6_firmware
*
siemenssimatic_ipc427e_firmware
*
siemenssimatic_ipc477e_firmware
*
siemenssimatic_ipc477e_pro_firmware
*
siemenssimatic_ipc527g_firmware
*
siemenssimatic_ipc547g_firmware
*
siemenssimatic_ipc627e_firmware
𝑥
< 25.02.10
siemenssimatic_ipc647e_firmware
𝑥
< 25.02.10
siemenssimatic_ipc677e_firmware
𝑥
< 25.02.10
siemenssimatic_ipc847e_firmware
𝑥
< 25.02.10
siemenssimatic_itp1000_firmware
*
𝑥
= Vulnerable software versions