ID

VAR-202011-0141


CVE

CVE-2020-12353


TITLE

Intel(R) Data Center Manager Console  Vulnerability regarding improper retention of permissions in

Trust: 0.8

sources: JVNDB: JVNDB-2020-013375

DESCRIPTION

Improper permissions in the Intel(R) Data Center Manager Console before version 3.6.2 may allow an authenticated user to potentially enable denial of service via network access. Intel Data Center Manager SDK is a data center management SDK (Software Development Kit) of Intel Corporation. This product mainly provides real-time power supply and heat dissipation data of equipment

Trust: 1.71

sources: NVD: CVE-2020-12353 // JVNDB: JVNDB-2020-013375 // VULHUB: VHN-165023

AFFECTED PRODUCTS

vendor:intelmodel:data center managerscope:ltversion:3.6.2

Trust: 1.0

vendor:インテルmodel:intel data center managerscope:eqversion:3.6.2

Trust: 0.8

vendor:インテルmodel:intel data center managerscope:eqversion: -

Trust: 0.8

sources: JVNDB: JVNDB-2020-013375 // NVD: CVE-2020-12353

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-12353
value: MEDIUM

Trust: 1.0

NVD: CVE-2020-12353
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-202011-856
value: MEDIUM

Trust: 0.6

VULHUB: VHN-165023
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2020-12353
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 8.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-165023
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 8.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2020-12353
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 3.6
version: 3.1

Trust: 1.0

NVD: CVE-2020-12353
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULHUB: VHN-165023 // JVNDB: JVNDB-2020-013375 // CNNVD: CNNVD-202011-856 // NVD: CVE-2020-12353

PROBLEMTYPE DATA

problemtype:CWE-281

Trust: 1.1

problemtype:Improper retention of permissions (CWE-281) [NVD Evaluation ]

Trust: 0.8

sources: VULHUB: VHN-165023 // JVNDB: JVNDB-2020-013375 // NVD: CVE-2020-12353

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202011-856

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202011-856

PATCH

title:INTEL-SA-00430url:https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00430.html

Trust: 0.8

title:Intel Data Center Manager Console Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=133837

Trust: 0.6

sources: JVNDB: JVNDB-2020-013375 // CNNVD: CNNVD-202011-856

EXTERNAL IDS

db:NVDid:CVE-2020-12353

Trust: 2.5

db:JVNDBid:JVNDB-2020-013375

Trust: 0.8

db:CNNVDid:CNNVD-202011-856

Trust: 0.7

db:AUSCERTid:ESB-2020.3953

Trust: 0.6

db:CNVDid:CNVD-2020-66315

Trust: 0.1

db:VULHUBid:VHN-165023

Trust: 0.1

sources: VULHUB: VHN-165023 // JVNDB: JVNDB-2020-013375 // CNNVD: CNNVD-202011-856 // NVD: CVE-2020-12353

REFERENCES

url:https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00430

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2020-12353

Trust: 1.4

url:https://www.auscert.org.au/bulletins/esb-2020.3953/

Trust: 0.6

sources: VULHUB: VHN-165023 // JVNDB: JVNDB-2020-013375 // CNNVD: CNNVD-202011-856 // NVD: CVE-2020-12353

SOURCES

db:VULHUBid:VHN-165023
db:JVNDBid:JVNDB-2020-013375
db:CNNVDid:CNNVD-202011-856
db:NVDid:CVE-2020-12353

LAST UPDATE DATE

2024-11-23T21:51:14.065000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-165023date:2020-11-24T00:00:00
db:JVNDBid:JVNDB-2020-013375date:2021-06-29T05:28:00
db:CNNVDid:CNNVD-202011-856date:2020-12-03T00:00:00
db:NVDid:CVE-2020-12353date:2024-11-21T04:59:33.643

SOURCES RELEASE DATE

db:VULHUBid:VHN-165023date:2020-11-12T00:00:00
db:JVNDBid:JVNDB-2020-013375date:2021-06-29T00:00:00
db:CNNVDid:CNNVD-202011-856date:2020-11-11T00:00:00
db:NVDid:CVE-2020-12353date:2020-11-12T19:15:14.503