ID

VAR-202008-1132


CVE

CVE-2020-8685


TITLE

Intel(R) LED Manager for NUC Authentication vulnerabilities in

Trust: 0.8

sources: JVNDB: JVNDB-2020-009491

DESCRIPTION

Improper authentication in subsystem for Intel (R) LED Manager for NUC before version 1.2.3 may allow privileged user to potentially enable denial of service via local access. Intel(R) LED Manager for NUC There is an authentication vulnerability in.Service operation interruption (DoS) It may be put into a state. The vulnerability is caused by improper authentication. A local attacker could exploit this vulnerability to cause a denial of service

Trust: 1.71

sources: NVD: CVE-2020-8685 // JVNDB: JVNDB-2020-009491 // VULHUB: VHN-186810

AFFECTED PRODUCTS

vendor:intelmodel:led manager for nucscope:ltversion:1.2.3

Trust: 1.0

vendor:intelmodel:led manager for nucscope:eqversion:1.2.3

Trust: 0.8

sources: JVNDB: JVNDB-2020-009491 // NVD: CVE-2020-8685

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-8685
value: MEDIUM

Trust: 1.0

NVD: JVNDB-2020-009491
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-202008-735
value: MEDIUM

Trust: 0.6

VULHUB: VHN-186810
value: LOW

Trust: 0.1

nvd@nist.gov: CVE-2020-8685
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:N/I:N/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

NVD: JVNDB-2020-009491
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:N/I:N/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

VULHUB: VHN-186810
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:N/I:N/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2020-8685
baseSeverity: MEDIUM
baseScore: 4.4
vectorString: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 0.8
impactScore: 3.6
version: 3.1

Trust: 1.0

NVD: JVNDB-2020-009491
baseSeverity: MEDIUM
baseScore: 4.4
vectorString: CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULHUB: VHN-186810 // JVNDB: JVNDB-2020-009491 // CNNVD: CNNVD-202008-735 // NVD: CVE-2020-8685

PROBLEMTYPE DATA

problemtype:CWE-287

Trust: 1.9

sources: VULHUB: VHN-186810 // JVNDB: JVNDB-2020-009491 // NVD: CVE-2020-8685

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-202008-735

TYPE

authorization issue

Trust: 0.6

sources: CNNVD: CNNVD-202008-735

CONFIGURATIONS

sources: JVNDB: JVNDB-2020-009491

PATCH

title:INTEL-SA-00376url:https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00376.html

Trust: 0.8

title:Intel LED Manager for NUC Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=126401

Trust: 0.6

sources: JVNDB: JVNDB-2020-009491 // CNNVD: CNNVD-202008-735

EXTERNAL IDS

db:NVDid:CVE-2020-8685

Trust: 2.5

db:JVNid:JVNVU99606488

Trust: 0.8

db:JVNDBid:JVNDB-2020-009491

Trust: 0.8

db:CNNVDid:CNNVD-202008-735

Trust: 0.7

db:VULHUBid:VHN-186810

Trust: 0.1

sources: VULHUB: VHN-186810 // JVNDB: JVNDB-2020-009491 // CNNVD: CNNVD-202008-735 // NVD: CVE-2020-8685

REFERENCES

url:https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00376.html

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2020-8685

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2020-8685

Trust: 0.8

url:https://jvn.jp/vu/jvnvu99606488

Trust: 0.8

sources: VULHUB: VHN-186810 // JVNDB: JVNDB-2020-009491 // CNNVD: CNNVD-202008-735 // NVD: CVE-2020-8685

SOURCES

db:VULHUBid:VHN-186810
db:JVNDBid:JVNDB-2020-009491
db:CNNVDid:CNNVD-202008-735
db:NVDid:CVE-2020-8685

LAST UPDATE DATE

2024-11-23T21:35:22.699000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-186810date:2020-08-19T00:00:00
db:JVNDBid:JVNDB-2020-009491date:2020-11-10T06:27:04
db:CNNVDid:CNNVD-202008-735date:2021-01-05T00:00:00
db:NVDid:CVE-2020-8685date:2024-11-21T05:39:15.127

SOURCES RELEASE DATE

db:VULHUBid:VHN-186810date:2020-08-13T00:00:00
db:JVNDBid:JVNDB-2020-009491date:2020-11-10T06:27:04
db:CNNVDid:CNNVD-202008-735date:2020-08-13T00:00:00
db:NVDid:CVE-2020-8685date:2020-08-13T04:15:13.803