Access of Uninitialized Pointer in Intel products - CVE-2020-12300
Published: August 14, 2020
Vulnerability identifier: #VU45728
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-12300
CWE-ID: CWE-824
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
Affected software
Intel Server Board S2600CW
Intel Server Board S2600KP
Intel Server Board S2600TP
Intel Server Boards S2600WT
Data Computing Appliance (DCA)
Intel Server Board S2600KP
Intel Server Board S2600TP
Intel Server Boards S2600WT
Data Computing Appliance (DCA)
How to mitigate CVE-2020-12300
Install updates from vendor's website.
Intel Server Board S2600CW - update to 1.01.0028
Intel Server Board S2600KP - update to 1.01.0028
Intel Server Board S2600TP - update to 1.01.0028
Intel Server Boards S2600WT - update to 01.01.0028
Data Computing Appliance (DCA) - addressed in versions Firmware tool 3H00, 4.2.1.0
Intel Server Board S2600KP - update to 1.01.0028
Intel Server Board S2600TP - update to 1.01.0028
Intel Server Boards S2600WT - update to 01.01.0028
Data Computing Appliance (DCA) - addressed in versions Firmware tool 3H00, 4.2.1.0