Permissions, Privileges, and Access Controls in Intel Ethernet 700 Series Controller Software - CVE-2020-8691

 

Permissions, Privileges, and Access Controls in Intel Ethernet 700 Series Controller Software - CVE-2020-8691

Published: November 12, 2020 / Updated: November 16, 2020


Vulnerability identifier: #VU48433
CSH Severity: Low
CVSS v4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-8691
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local administrator to escalate privileges on the system.

The vulnerability exists due to a logic issue in the firmware, which leads to privilege escalation and denial of service (DoS) condition.


Affected software

Intel Ethernet 700 Series Controller Software
F5OS
Dell EMC VxRail Appliance
Precision 7920 Rack

How to mitigate CVE-2020-8691

Install updates from vendor's website.

Intel Ethernet 700 Series Controller Software - update to 7.3
Dell EMC VxRail Appliance - update to 7.0.203
Precision 7920 Rack - update to 20.0.17

External References

Related Security Bulletins