Risk | Low |
Patch available | YES |
Number of vulnerabilities | 1 |
CVE-ID | CVE-2020-0527 |
CWE-ID | CWE-200 |
Exploitation vector | Local |
Public exploit | N/A |
Vulnerable software |
Intel SSD D3-S4510 Series Hardware solutions / Other hardware appliances Intel SSD DC P4510 Series Hardware solutions / Other hardware appliances Intel SSD DC P4610 Series Hardware solutions / Other hardware appliances Intel SSD DC P4618 Series Hardware solutions / Other hardware appliances Intel SSD DC P4511 Series Hardware solutions / Other hardware appliances Intel SSD D5-P4326 Series Hardware solutions / Other hardware appliances Intel SSD D5-P4320 Series Hardware solutions / Other hardware appliances Intel SSD D5-P4420 Series Hardware solutions / Other hardware appliances |
Vendor | Intel |
Security Bulletin
This security bulletin contains one low risk vulnerability.
EUVDB-ID: #VU28949
Risk: Low
CVSSv4.0: 4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2020-0527
CWE-ID:
CWE-200 - Information exposure
Exploit availability: No
DescriptionThe vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to insufficient control flow management. A local administrator can gain unauthorized access to sensitive information on the system.
MitigationInstall updates from vendor's website.
Vulnerable software versionsIntel SSD D3-S4510 Series: before XC311120
Intel SSD DC P4510 Series: before VDV10170
Intel SSD DC P4610 Series: before VDV10170
Intel SSD DC P4618 Series: before VDV10170
Intel SSD DC P4511 Series: before VDV10170
Intel SSD D5-P4326 Series: All versions
Intel SSD D5-P4320 Series: All versions
Intel SSD D5-P4420 Series: All versions
CPE2.3https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00266.html
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.