Cross-site scripting in Intel products - CVE-2020-8723
Published: August 14, 2020
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote attacker on the local network can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Affected software
Intel Server Board S2600BP
Intel Compute Module HNS2600BP
Intel Server Board S2600ST
Intel Server Board S2600WF
Intel Server System R2000WF
Intel Server System R1000WF
Intel Server Board S1200SP
Intel Server System LR1304SP
Intel Server System R1000WT
Intel Server System R1000SP
Intel Server Board S2600TP
Intel Compute Module HNS2600TP
Intel Server Board S2600KP
Intel Compute Module HNS2600KP
Intel Server Board S2600CW
Intel Server Boards S2600WT
Intel Server System R2000WT
Data Computing Appliance (DCA)
EMC ECS
How to mitigate CVE-2020-8723
Intel Server Board S2600BP - update to 02.01.0012
Intel Compute Module HNS2600BP - update to 02.01.0012
Intel Server Board S2600ST - update to 02.01.0011
Intel Server Board S2600WF - update to 02.01.0012
Intel Server System R2000WF - update to 02.01.0012
Intel Server System R1000WF - update to 02.01.0012
Intel Server Board S1200SP - update to 03.01.0049
Intel Server System LR1304SP - update to 03.01.0049
Intel Server System R1000WT - update to 01.01.0029
Intel Server System R1000SP - update to 03.01.0049
Intel Server Board S2600TP - update to 1.01.0029
Intel Compute Module HNS2600TP - update to 1.01.0029
Intel Server Board S2600KP - update to 1.01.0029
Intel Compute Module HNS2600KP - update to 1.01.0029
Intel Server Board S2600CW - update to 01.01.0029
Intel Server Boards S2600WT - update to 01.01.0029
Intel Server System R2000WT - update to 01.01.0029
Data Computing Appliance (DCA) - addressed in versions Firmware tool 3H00, 4.2.1.0
EMC ECS - addressed in versions 3.5.1.1, 3.6