Race condition in Intel products - CVE-2020-8670
Published: June 16, 2021
Vulnerability identifier: #VU54162
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-8670
CWE-ID: CWE-362
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a race condition in the firmware . A local administrator can exploit the race and gain unauthorized access to sensitive information and escalate privileges on the system.
Affected software
Intel Xeon Processor E5 v3 Family
11th Generation Intel Core Processors
Intel Core Processors with Intel Hybrid Technology
Intel Core X-series Processors
6th Generation Intel Core Processors
7th Generation Intel Core Processors
8th Generation Intel Core Processors
10th Generation Intel Core Processors
Intel Xeon W Processors
2nd Generation Intel Xeon Scalable Processors
Intel Xeon Processor E5 v4 Family
Intel Xeon Processor E3 v5 Family
Intel Xeon Processor E3 v6 Family
Intel Xeon Processor E7 v4 Family
Intel Xeon Processor E Family
Intel Xeon D Processors
SIMATIC IPC527GE
SINUMERIK ONE PPU 1740
SINUMERIK ONE / SINUMERIK 840D sl Handheld Terminal HT 10
SINUMERIK MC MCU 1720
SINUMERIK 828D HW PPU.4
SIMATIC S7-1500 CPU 1518F-4 PN-DP MFP
SIMATIC S7-1500 CPU 1518-4 PN/DP MFP
SIMATIC Drive Controller
SIMATIC IPC477E Pro
SIMATIC IPC127E
SIMATIC Field PG M6
SIMATIC Field PG M5
PowerScale OneFS
SIMATIC IPC627E
SIMATIC IPC647E
SIMATIC IPC677E
SIMATIC IPC847E
Intel Xeon Scalable Processors
SIMATIC ITP1000
SIMATIC IPC547G
SIMATIC IPC477E
SIMATIC IPC427E
SIMATIC ET 200SP Open Controller CPU 1515SP PC2
Edgeline EL300 Converged Edge System
RecoverPoint Classic
Dell EMC VxRail Appliance
11th Generation Intel Core Processors
Intel Core Processors with Intel Hybrid Technology
Intel Core X-series Processors
6th Generation Intel Core Processors
7th Generation Intel Core Processors
8th Generation Intel Core Processors
10th Generation Intel Core Processors
Intel Xeon W Processors
2nd Generation Intel Xeon Scalable Processors
Intel Xeon Processor E5 v4 Family
Intel Xeon Processor E3 v5 Family
Intel Xeon Processor E3 v6 Family
Intel Xeon Processor E7 v4 Family
Intel Xeon Processor E Family
Intel Xeon D Processors
SIMATIC IPC527GE
SINUMERIK ONE PPU 1740
SINUMERIK ONE / SINUMERIK 840D sl Handheld Terminal HT 10
SINUMERIK MC MCU 1720
SINUMERIK 828D HW PPU.4
SIMATIC S7-1500 CPU 1518F-4 PN-DP MFP
SIMATIC S7-1500 CPU 1518-4 PN/DP MFP
SIMATIC Drive Controller
SIMATIC IPC477E Pro
SIMATIC IPC127E
SIMATIC Field PG M6
SIMATIC Field PG M5
PowerScale OneFS
SIMATIC IPC627E
SIMATIC IPC647E
SIMATIC IPC677E
SIMATIC IPC847E
Intel Xeon Scalable Processors
SIMATIC ITP1000
SIMATIC IPC547G
SIMATIC IPC477E
SIMATIC IPC427E
SIMATIC ET 200SP Open Controller CPU 1515SP PC2
Edgeline EL300 Converged Edge System
RecoverPoint Classic
Dell EMC VxRail Appliance
How to mitigate CVE-2020-8670
Install updates from vendor's website.
Edgeline EL300 Converged Edge System - addressed in versions EL01_1.40, 11.8.86.3909
RecoverPoint Classic - update to 5.1 SP4 P5
Dell EMC VxRail Appliance - update to 7.0.300
PowerScale OneFS - update to 12.0
SIMATIC IPC627E - update to 25.02.10
SIMATIC IPC647E - update to 25.02.10
SIMATIC IPC677E - update to 25.02.10
SIMATIC IPC847E - update to 25.02.10
RecoverPoint Classic - update to 5.1 SP4 P5
Dell EMC VxRail Appliance - update to 7.0.300
PowerScale OneFS - update to 12.0
SIMATIC IPC627E - update to 25.02.10
SIMATIC IPC647E - update to 25.02.10
SIMATIC IPC677E - update to 25.02.10
SIMATIC IPC847E - update to 25.02.10
External References
Related Security Bulletins
- Multiple vulnerabilities in Intel Processors
- Multiple vulnerabilities in Siemens Industrial Products Intel CPUs
- Multiple vulnerabilities in Dell EMC VxRail Appliance
- Multiple vulnerabilities in HPE Edgeline EL300 Converged Edge Systems
- Multiple vulnerabilities in Dell PowerScale OneFS
- Multiple vulnerabilities in Dell RecoverPoint Classic