ID

VAR-202102-0088


CVE

CVE-2020-12339


TITLE

WebRTC  for  Intel(R) Collaboration Suite  Vulnerability in

Trust: 0.8

sources: JVNDB: JVNDB-2020-016135

DESCRIPTION

Insufficient control flow management in the API for the Intel(R) Collaboration Suite for WebRTC before version 4.3.1 may allow an authenticated user to potentially enable escalation of privilege via network access. WebRTC for Intel(R) Collaboration Suite Contains an unspecified vulnerability.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. There is a permission and access control vulnerability in Intel Collaboration Suite for WebRTC. The vulnerability stems from the lack of effective permission and access control measures in network systems or products

Trust: 1.71

sources: NVD: CVE-2020-12339 // JVNDB: JVNDB-2020-016135 // VULHUB: VHN-165007

AFFECTED PRODUCTS

vendor:intelmodel:collaboration suitescope:ltversion:4.3.1

Trust: 1.0

vendor:インテルmodel:collaboration suitescope:eqversion: -

Trust: 0.8

vendor:インテルmodel:collaboration suitescope:eqversion:4.3.1

Trust: 0.8

sources: JVNDB: JVNDB-2020-016135 // NVD: CVE-2020-12339

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-12339
value: HIGH

Trust: 1.0

NVD: CVE-2020-12339
value: HIGH

Trust: 0.8

CNNVD: CNNVD-202102-995
value: HIGH

Trust: 0.6

VULHUB: VHN-165007
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2020-12339
severity: MEDIUM
baseScore: 6.5
vectorString: AV:N/AC:L/AU:S/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-165007
severity: MEDIUM
baseScore: 6.5
vectorString: AV:N/AC:L/AU:S/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2020-12339
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 5.9
version: 3.1

Trust: 1.0

NVD: CVE-2020-12339
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULHUB: VHN-165007 // JVNDB: JVNDB-2020-016135 // CNNVD: CNNVD-202102-995 // NVD: CVE-2020-12339

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

problemtype:Other (CWE-Other) [NVD Evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2020-016135 // NVD: CVE-2020-12339

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202102-995

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202102-995

PATCH

title:INTEL-SA-00425url:https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00425.html

Trust: 0.8

title:Intel Collaboration Suite for WebRTC Fixes for permissions and access control issues vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=142615

Trust: 0.6

sources: JVNDB: JVNDB-2020-016135 // CNNVD: CNNVD-202102-995

EXTERNAL IDS

db:NVDid:CVE-2020-12339

Trust: 2.5

db:JVNid:JVNVU93808918

Trust: 0.8

db:JVNDBid:JVNDB-2020-016135

Trust: 0.8

db:AUSCERTid:ESB-2021.0484

Trust: 0.6

db:CNNVDid:CNNVD-202102-995

Trust: 0.6

db:VULHUBid:VHN-165007

Trust: 0.1

sources: VULHUB: VHN-165007 // JVNDB: JVNDB-2020-016135 // CNNVD: CNNVD-202102-995 // NVD: CVE-2020-12339

REFERENCES

url:https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00425.html

Trust: 1.7

url:https://jvn.jp/vu/jvnvu93808918/index.html

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2020-12339

Trust: 0.8

url:https://www.auscert.org.au/bulletins/esb-2021.0484

Trust: 0.6

sources: VULHUB: VHN-165007 // JVNDB: JVNDB-2020-016135 // CNNVD: CNNVD-202102-995 // NVD: CVE-2020-12339

SOURCES

db:VULHUBid:VHN-165007
db:JVNDBid:JVNDB-2020-016135
db:CNNVDid:CNNVD-202102-995
db:NVDid:CVE-2020-12339

LAST UPDATE DATE

2024-11-23T19:27:04.301000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-165007date:2021-02-22T00:00:00
db:JVNDBid:JVNDB-2020-016135date:2021-11-09T09:08:00
db:CNNVDid:CNNVD-202102-995date:2022-03-08T00:00:00
db:NVDid:CVE-2020-12339date:2024-11-21T04:59:32.710

SOURCES RELEASE DATE

db:VULHUBid:VHN-165007date:2021-02-17T00:00:00
db:JVNDBid:JVNDB-2020-016135date:2021-11-09T00:00:00
db:CNNVDid:CNNVD-202102-995date:2021-02-10T00:00:00
db:NVDid:CVE-2020-12339date:2021-02-17T14:15:15.030