Unknown · CVSS Not scored
Out-of-bounds read in subsystem for Intel(R) AMT, Intel(R) ISM versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow an unauthenticated user to potentially enable information disclosure via network access.
Published Nov 12, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Uncaught exception in the Intel(R) 50GbE IP Core for Intel(R) Quartus Prime before version 20.2 may allow an authenticated user to potentially enable denial of service via local access.
Published Nov 12, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Use after free in Kernel Mode Driver for Intel(R) TXE versions before 3.1.80 and 4.0.30 may allow an authenticated user to potentially enable escalation of privilege via local access.
Published Nov 12, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Inadequate encryption strength in subsystem for Intel(R) CSME versions before 13.0.40 and 13.30.10 may allow an unauthenticated user to potentially enable information disclosure via physical access.
Published Nov 12, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Race condition in subsystem for Intel(R) CSME versions before 12.0.70 and 14.0.45, Intel(R) SPS versions before E5_04.01.04.400 and E3_05.01.04.200 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
Published Nov 12, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Improper access control in BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
Published Nov 12, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Improper input validation in subsystem for Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow a privileged user to potentially enable escalation of privilege via local access.
Published Nov 12, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Improper conditions check in the Intel(R) SGX DCAP software before version 1.6 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
Published Nov 12, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Integer overflow in subsystem for Intel(R) AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 14.0.45 may allow a privileged user to potentially enable escalation of privilege via local access.
Published Nov 12, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Improper initialization in subsystem for Intel(R) CSME versions before12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE versions before 4.0.30 Intel(R) SPS versions before E3_05.01.04.200 may allow a privileged user to potentially enable escalation of privilege via local access.
Published Nov 12, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Out-of-bounds read in subsystem for Intel(R) AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow a privileged user to potentially enable escalation of privilege via local access.
Published Nov 12, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Improper buffer restrictions in the Intel(R) Stratix(R) 10 FPGA firmware provided with the Intel(R) Quartus(R) Prime Pro software before version 20.1 may allow an unauthenticated user to potentially enable escalation of privilege and/or information disclosure via physical access.
Published Nov 12, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Insufficient control flow management in subsystem for Intel(R) CSME versions before 11.8.80, Intel(R) TXE versions before 3.1.80 may allow an unauthenticated user to potentially enable information disclosure via physical access.
Published Nov 12, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Out-of-bounds read in subsystem for Intel(R) AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow an unauthenticated user to potentially enable information disclosure and/or denial of service via network access.
Published Nov 12, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Out-of-bounds write in IPv6 subsystem for Intel(R) AMT, Intel(R) ISM versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 14.0.45 may allow an unauthenticated user to potentially enable escalation of privileges via network access.
Published Nov 12, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Use of potentially dangerous function in Intel BIOS platform sample code for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via local access.
Published Nov 12, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Out-of-bounds read in subsystem for Intel(R) AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.
Published Nov 12, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Out of bounds write in Intel BIOS platform sample code for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
Published Nov 12, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Improper permissions in the installer for the Intel(R) Thunderbolt(TM) non-DCH driver, all versions, for Windows may allow an authenticated user to potentially enable escalation of privilege via local access.
Published Nov 17, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Out-of-bounds read in DHCP subsystem for Intel(R) AMT, Intel(R) ISM versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow an unauthenticated user to potentially enable information disclosure via network access.
Published Nov 12, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Improper conditions check in Intel BIOS platform sample code for some Intel(R) Processors before may allow a privileged user to potentially enable escalation of privilege via local access.
Published Nov 12, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Insufficient control flow management in subsystem for Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25 , Intel(R) TXE versions before 3.1.80 and 4.0.30 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
Published Nov 12, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Integer overflow in subsystem for Intel(R) AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
Published Nov 12, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Protection mechanism failure in Intel(R) Ethernet 700 Series Controllers before version 7.3 may allow a privileged user to potentially enable escalation of privilege and/or denial of service via local access.
Published Nov 12, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A logic issue in the firmware of the Intel(R) Ethernet 700 Series Controllers may allow a privileged user to potentially enable escalation of privilege and/or denial of service via local access.
Published Nov 12, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Improper access control in the Intel(R) Visual Compute Accelerator 2, all versions, may allow a privileged user to potentially enable denial of service via local access.
Published Nov 12, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
SANtricity OS Controller Software versions 11.30 and higher are susceptible to a vulnerability which allows an unauthenticated attacker with access to the system to cause a Denial of Service (DoS).
Published Nov 6, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Improper removal of sensitive information before storage or transfer in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Published Nov 12, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Improper input validation in the Intel(R) Data Center Manager Console before version 3.6.2 may allow an authenticated user to potentially enable information disclosure via network access.
Published Nov 12, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Improper buffer restrictions in the firmware of the Intel(R) Ethernet 700 Series Controllers may allow a privileged user to potentially enable escalation of privilege and/or denial of service via local access.
Published Nov 12, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Observable discrepancy in the RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
Published Nov 12, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Published Nov 12, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Insufficient access control in the firmware of the Intel(R) Ethernet 700 Series Controllers before version 7.3 may allow a privileged user to potentially enable escalation of privilege and/or denial of service via local access.
Published Nov 12, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Insecure default initialization of resource in Intel(R) Boot Guard in Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE versions before 3.1.80 and 4.0.30, Intel(R) SPS versions before E5_04.01.04.400, E3_04.01.04.200, SoC-X_04.00.04.200 and SoC-A_04.00.04.300 may allow an unauthenticated user to potentially enable escalation of privileges via physical access.
Published Nov 12, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Insufficient access control in the Linux kernel driver for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Published Nov 12, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Improper access control in the Intel(R) Visual Compute Accelerator 2, all versions, may allow a privileged user to potentially enable escalation of privilege via local access.
Published Nov 12, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Element Software versions prior to 12.2 and HCI versions prior to 1.8P1 are susceptible to a vulnerability which could allow an attacker to discover sensitive information by intercepting its transmission within an https session.
Published Nov 13, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
SANtricity OS Controller Software versions 11.50.1 and higher are susceptible to a vulnerability which could allow an attacker to discover sensitive information by intercepting its transmission within an https session.
Published Nov 6, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Element Software versions prior to 12.2 and HCI versions prior to 1.8P1 are susceptible to a vulnerability which could allow an authenticated user to view sensitive information.
Published Nov 13, 2020 · Updated Aug 4, 2024
High · CVSS 7.8
A privilege escalation vulnerability was reported in Lenovo PCManager prior to version 3.0.50.9162 that could allow an authenticated user to execute code with elevated privileges.
Published Nov 30, 2020 · Updated Aug 4, 2024
Medium · CVSS 6.4
A potential vulnerability in the SMI callback function used in the VariableServiceSmm driver in some Lenovo Notebook models may allow arbitrary code execution.
Published Nov 11, 2020 · Updated Aug 4, 2024
Medium · CVSS 6.7
Prior to August 10, 2020, some Lenovo Desktop and Workstation systems were shipped with the Embedded Host Based Configuration (EHBC) feature of Intel AMT enabled. This could allow an administrative user with local access to configure Intel AMT.
Published Nov 11, 2020 · Updated Aug 4, 2024
Low · CVSS 2.4
In some Lenovo Desktop models, the Configuration Change Detection BIOS setting failed to detect SATA configuration changes.
Published Nov 11, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The implementation of Brave Desktop's privacy-preserving analytics system (P3A) between 1.1 and 1.18.35 logged the timestamp of when the user last opened an incognito window, including Tor windows. The intended behavior was to log the timestamp for incognito windows excluding Tor windows. Note that if a user has P3A enabled, the timestamp is not sent to Brave's server, but rather a value from:Used in last 24hUsed in last week but not 24hUsed in last 28 days but not weekEver used but not in last 28 daysNever usedThe privacy risk is low because a local attacker with disk access cannot tell if the timestamp corresponds to a Tor window or a non-Tor incognito window.
Published Nov 9, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Improper access control in Nextcloud Social app version 0.3.1 allowed to read posts of any user.
Published Nov 19, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Prototype pollution vulnerability in json8-merge-patch npm package < 1.0.3 may allow attackers to inject or modify methods and properties of the global object constructor.
Published Nov 9, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Missing validation of server certificates for out-going connections in Nextcloud Social < 0.4.0 allowed a man-in-the-middle attack.
Published Nov 19, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Privilege escalation of an authenticated user to root in Citrix SD-WAN center versions before 11.2.2, 11.1.2b and 10.2.8.
Published Nov 16, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Authentication Bypass resulting in exposure of SD-WAN functionality in Citrix SD-WAN Center versions before 11.2.2, 11.1.2b and 10.2.8
Published Nov 16, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Unauthenticated remote code execution with root privileges in Citrix SD-WAN Center versions before 11.2.2, 11.1.2b and 10.2.8
Published Nov 16, 2020 · Updated Aug 4, 2024