ID

VAR-202004-0366


CVE

CVE-2020-0547


TITLE

Intel(R) Data Migration Software Vulnerability regarding improper default permissions in

Trust: 0.8

sources: JVNDB: JVNDB-2020-004593

DESCRIPTION

Incorrect default permissions in the installer for Intel(R) Data Migration Software versions 3.3 and earlier may allow an authenticated user to potentially enable escalation of privilege via local access. Intel(R) Data Migration Software There is a vulnerability in improper default permissions.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be put into a state. Intel Data Migration Software is a set of data migration software from Intel Corporation of the United States. The software supports data migration between two storage drives. An attacker could exploit this vulnerability to elevate privileges

Trust: 1.71

sources: NVD: CVE-2020-0547 // JVNDB: JVNDB-2020-004593 // VULHUB: VHN-161981

AFFECTED PRODUCTS

vendor:intelmodel:data migrationscope:lteversion:3.3

Trust: 1.0

vendor:intelmodel:data migration softwarescope:eqversion:3.3

Trust: 0.8

sources: JVNDB: JVNDB-2020-004593 // NVD: CVE-2020-0547

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-0547
value: HIGH

Trust: 1.0

NVD: JVNDB-2020-004593
value: HIGH

Trust: 0.8

CNNVD: CNNVD-202004-1203
value: MEDIUM

Trust: 0.6

VULHUB: VHN-161981
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2020-0547
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

NVD: JVNDB-2020-004593
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

VULHUB: VHN-161981
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2020-0547
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.1

Trust: 1.0

NVD: JVNDB-2020-004593
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULHUB: VHN-161981 // JVNDB: JVNDB-2020-004593 // CNNVD: CNNVD-202004-1203 // NVD: CVE-2020-0547

PROBLEMTYPE DATA

problemtype:CWE-276

Trust: 1.9

sources: VULHUB: VHN-161981 // JVNDB: JVNDB-2020-004593 // NVD: CVE-2020-0547

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202004-1203

CONFIGURATIONS

sources: JVNDB: JVNDB-2020-004593

PATCH

title:INTEL-SA-00327url:https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00327.html

Trust: 0.8

sources: JVNDB: JVNDB-2020-004593

EXTERNAL IDS

db:NVDid:CVE-2020-0547

Trust: 2.5

db:JVNid:JVNVU97303667

Trust: 0.8

db:JVNDBid:JVNDB-2020-004593

Trust: 0.8

db:CNNVDid:CNNVD-202004-1203

Trust: 0.7

db:CNVDid:CNVD-2020-33647

Trust: 0.1

db:VULHUBid:VHN-161981

Trust: 0.1

sources: VULHUB: VHN-161981 // JVNDB: JVNDB-2020-004593 // CNNVD: CNNVD-202004-1203 // NVD: CVE-2020-0547

REFERENCES

url:https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00327.html

Trust: 1.7

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2020-0547

Trust: 0.8

url:https://jvn.jp/vu/jvnvu97303667/

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2020-0547\

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2020-0547

Trust: 0.6

sources: VULHUB: VHN-161981 // JVNDB: JVNDB-2020-004593 // CNNVD: CNNVD-202004-1203 // NVD: CVE-2020-0547

SOURCES

db:VULHUBid:VHN-161981
db:JVNDBid:JVNDB-2020-004593
db:CNNVDid:CNNVD-202004-1203
db:NVDid:CVE-2020-0547

LAST UPDATE DATE

2024-11-23T19:27:34.299000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-161981date:2020-04-23T00:00:00
db:JVNDBid:JVNDB-2020-004593date:2020-05-21T00:00:00
db:CNNVDid:CNNVD-202004-1203date:2020-04-22T00:00:00
db:NVDid:CVE-2020-0547date:2024-11-21T04:53:43.050

SOURCES RELEASE DATE

db:VULHUBid:VHN-161981date:2020-04-15T00:00:00
db:JVNDBid:JVNDB-2020-004593date:2020-05-21T00:00:00
db:CNNVDid:CNNVD-202004-1203date:2020-04-15T00:00:00
db:NVDid:CVE-2020-0547date:2020-04-15T17:15:13.890