ID

VAR-202102-0270


CVE

CVE-2020-24491


TITLE

Intel(R) 10th Generation Core Processor  Input confirmation vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2020-016091

DESCRIPTION

Debug message containing addresses of memory transactions in some Intel(R) 10th Generation Core Processors supporting SGX may allow a privileged user to potentially enable information disclosure via local access. Intel(R) 10th Generation Core Processor Is vulnerable to input validation.Information may be obtained. There is no information about this vulnerability at present. Please keep an eye on CNNVD or manufacturer announcements

Trust: 1.71

sources: NVD: CVE-2020-24491 // JVNDB: JVNDB-2020-016091 // VULHUB: VHN-178375

AFFECTED PRODUCTS

vendor:intelmodel:core i3scope:eqversion:1000g1

Trust: 1.0

vendor:intelmodel:core i3scope:eqversion:1005g1

Trust: 1.0

vendor:intelmodel:core i3scope:eqversion:1000g4

Trust: 1.0

vendor:intelmodel:core i5scope:eqversion:1030g7

Trust: 1.0

vendor:intelmodel:core i5scope:eqversion:1035g4

Trust: 1.0

vendor:intelmodel:core i5scope:eqversion:1035g1

Trust: 1.0

vendor:intelmodel:core i5scope:eqversion:1030g4

Trust: 1.0

vendor:intelmodel:core i7scope:eqversion:1060g7

Trust: 1.0

vendor:intelmodel:core i7scope:eqversion:1065g7

Trust: 1.0

vendor:intelmodel:core i5scope:eqversion:1035g7

Trust: 1.0

vendor:インテルmodel:intel core i5scope: - version: -

Trust: 0.8

vendor:インテルmodel:intel core i7scope: - version: -

Trust: 0.8

vendor:インテルmodel:intel core i3scope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2020-016091 // NVD: CVE-2020-24491

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-24491
value: MEDIUM

Trust: 1.0

NVD: CVE-2020-24491
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-202102-893
value: MEDIUM

Trust: 0.6

VULHUB: VHN-178375
value: LOW

Trust: 0.1

nvd@nist.gov: CVE-2020-24491
severity: LOW
baseScore: 1.9
vectorString: AV:L/AC:M/AU:N/C:P/I:N/A:N
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.4
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-178375
severity: LOW
baseScore: 1.9
vectorString: AV:L/AC:M/AU:N/C:P/I:N/A:N
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.4
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2020-24491
baseSeverity: MEDIUM
baseScore: 4.4
vectorString: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 0.8
impactScore: 3.6
version: 3.1

Trust: 1.0

NVD: CVE-2020-24491
baseSeverity: MEDIUM
baseScore: 4.4
vectorString: CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULHUB: VHN-178375 // JVNDB: JVNDB-2020-016091 // CNNVD: CNNVD-202102-893 // NVD: CVE-2020-24491

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.1

problemtype:Incorrect input confirmation (CWE-20) [NVD Evaluation ]

Trust: 0.8

problemtype:CWE-312

Trust: 0.1

sources: VULHUB: VHN-178375 // JVNDB: JVNDB-2020-016091 // NVD: CVE-2020-24491

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-202102-893

TYPE

information disclosure

Trust: 0.6

sources: CNNVD: CNNVD-202102-893

PATCH

title:INTEL-SA-00455url:https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00455.html

Trust: 0.8

title:Intel 10th Generation Core Processors Repair measures for information disclosure vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=142242

Trust: 0.6

sources: JVNDB: JVNDB-2020-016091 // CNNVD: CNNVD-202102-893

EXTERNAL IDS

db:NVDid:CVE-2020-24491

Trust: 2.5

db:JVNid:JVNVU93808918

Trust: 0.8

db:JVNDBid:JVNDB-2020-016091

Trust: 0.8

db:LENOVOid:LEN-51719

Trust: 0.6

db:CNNVDid:CNNVD-202102-893

Trust: 0.6

db:VULHUBid:VHN-178375

Trust: 0.1

sources: VULHUB: VHN-178375 // JVNDB: JVNDB-2020-016091 // CNNVD: CNNVD-202102-893 // NVD: CVE-2020-24491

REFERENCES

url:https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00455.html

Trust: 1.7

url:https://jvn.jp/vu/jvnvu93808918/

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2020-24491

Trust: 0.8

url:https://support.lenovo.com/us/en/product_security/len-51719

Trust: 0.6

sources: VULHUB: VHN-178375 // JVNDB: JVNDB-2020-016091 // CNNVD: CNNVD-202102-893 // NVD: CVE-2020-24491

SOURCES

db:VULHUBid:VHN-178375
db:JVNDBid:JVNDB-2020-016091
db:CNNVDid:CNNVD-202102-893
db:NVDid:CVE-2020-24491

LAST UPDATE DATE

2024-11-23T20:15:51.172000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-178375date:2021-07-21T00:00:00
db:JVNDBid:JVNDB-2020-016091date:2021-11-05T07:06:00
db:CNNVDid:CNNVD-202102-893date:2021-12-06T00:00:00
db:NVDid:CVE-2020-24491date:2024-11-21T05:14:54.440

SOURCES RELEASE DATE

db:VULHUBid:VHN-178375date:2021-02-17T00:00:00
db:JVNDBid:JVNDB-2020-016091date:2021-11-05T00:00:00
db:CNNVDid:CNNVD-202102-893date:2021-02-09T00:00:00
db:NVDid:CVE-2020-24491date:2021-02-17T14:15:17.653