Risk | Low |
Patch available | YES |
Number of vulnerabilities | 3 |
CVE-ID | CVE-2020-8694 CVE-2020-8695 CVE-2020-12912 |
CWE-ID | CWE-284 CWE-204 CWE-200 |
Exploitation vector | Local |
Public exploit | N/A |
Vulnerable software Subscribe |
containerd Other software / Other software solutions |
Vendor | containerd |
Security Bulletin
This security bulletin contains information about 3 vulnerabilities.
EUVDB-ID: #VU48371
Risk: Low
CVSSv3.1: 4.9 [CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C]
CVE-ID: CVE-2020-8694
CWE-ID:
CWE-284 - Improper Access Control
Exploit availability: No
DescriptionThe vulnerability allows a local user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in the Linux kernel driver. A local user can bypass implemented security restrictions and gain unauthorized access to sensitive information on the system.
Affected products:
Product Collection |
Vertical Segment |
CPUID |
8th Generation Intel® Core™ Processor Family |
Mobile |
806E9 |
10th Generation Intel® Core™ Processor Family |
Mobile |
806EC |
8th Generation Intel® Core™ Processor Family |
Mobile |
906EA |
9th Generation Intel® Core™ Processor Family |
Mobile |
906EC |
8th Generation Intel® Core™ Processor Family |
Desktop |
906EA |
9th Generation Intel® Core™ Processor Family |
Desktop |
906EC |
Intel® Xeon® Processor E Family |
Server Workstation AMT Server |
906EA |
8th Generation Intel® Core™ Processor Family |
Mobile |
806EA |
8th Generation Intel® Core™ Processor Family Intel® Pentium® Gold Processor Series Intel® Celeron® Processor G Series |
Desktop |
906EB |
Intel® Xeon® Processor E Family |
Server Workstation AMT Server |
906EA |
8th Generation Intel® Core™ Processor Family |
Desktop |
906EA |
9th Generation Intel® Core™ Processor Family |
Desktop |
906ED |
9th Generation Intel® Core™ Processor Family |
Desktop |
906ED |
10th Generation Intel® Core™ Processor Family |
Mobile |
A0660 |
10th Generation Intel® Core™ Processor Family |
Mobile |
A0661 |
10th Generation Intel® Core™ Processor Family |
Mobile |
806EC |
10th Generation Intel® Core™ Processor Family |
Desktop |
A0653 |
10th Generation Intel® Core™ Processor Family |
Mobile |
A0655 |
10th Generation Intel® Core™ Processor Family |
Mobile |
A0652 |
Intel® Pentium® Processor Silver Series Intel® Celeron® Processor J Series Intel® Celeron® Processor N Series |
Desktop Mobile Embedded |
706A1 |
Intel® Pentium® Processor Silver Series Intel® Celeron® Processor J Series Intel® Celeron® Processor N Series |
Desktop Mobile Embedded |
706A8 |
10th Generation Intel® Core™ Processor Family |
Mobile |
706E5 |
8th Generation Intel® Core™ Processor Family |
Mobile |
906E9 |
7th Generation Intel® Core™ Processor Family |
Mobile Embedded |
906E9 |
8th Generation Intel® Core™ Processor Family |
Mobile |
806EA |
7th Generation Intel® Core™ Processor Family |
Desktop Embedded |
906E9 |
7th Generation Intel® Core™ Processor Family |
Mobile |
806E9 |
7th Generation Intel® Core™ Processor Family |
Mobile |
806E9 |
Intel® Core™ X-series Processors |
Desktop |
906E9 |
Intel® Xeon® Processor E3 v6 Family |
Server Workstation AMT Server |
906E9 |
7th Generation Intel® Core™ Processor Family |
Mobile |
806E9 |
6th Generation Intel® Core™ Processor Family |
Mobile |
506E3 |
6th Generation Intel® Core™ Processor Family |
Desktop Embedded |
506E3 |
6th Generation Intel® Core™ Processors |
Mobile |
406E3 |
6th Generation Intel® Core™ Processor Family |
Mobile |
406E3 |
Intel® Xeon® Processor E3 v5 Family |
Server Workstation AMT Server |
506E3 |
6th Generation Intel® Core™ Processor Family |
Mobile |
406E3 |
8th Generation Intel® Core™ Processors |
Mobile |
806EB |
8th Generation Intel® Core™ Processors |
Mobile |
806EC |
Install update from vendor's website.
Vulnerable software versionscontainerd: 1.0.0 - 1.7.10
CPE2.3http://github.com/containerd/containerd/security/advisories/GHSA-7ww5-4wqc-m92c
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU48372
Risk: Low
CVSSv3.1: 4.6 [CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C]
CVE-ID: CVE-2020-8695
CWE-ID:
CWE-204 - Observable Response Discrepancy
Exploit availability: No
DescriptionThe vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to observable discrepancy in the Running Average Power Limit (RAPL) Interface. A local administrator can gain access to sensitive information on the target system.
Affected products:
Product Collection |
Vertical Segment |
CPUID |
8th Generation Intel® Core™ Processor Family |
Mobile |
806E9 |
10th Generation Intel® Core™ Processor Family |
Mobile |
806EC |
8th Generation Intel® Core™ Processor Family |
Mobile |
906EA |
9th Generation Intel® Core™ Processor Family |
Mobile |
906EC |
8th Generation Intel® Core™ Processor Family |
Desktop |
906EA |
9th Generation Intel® Core™ Processor Family |
Desktop |
906EC |
Intel® Xeon® Processor E Family |
Server Workstation AMT Server |
906EA |
8th Generation Intel® Core™ Processor Family |
Mobile |
806EA |
8th Generation Intel® Core™ Processor Family Intel® Pentium® Gold Processor Series Intel® Celeron® Processor G Series |
Desktop |
906EB |
Intel® Xeon® Processor E Family |
Server Workstation AMT Server |
906EA |
8th Generation Intel® Core™ Processor Family |
Desktop |
906EA |
9th Generation Intel® Core™ Processor Family |
Desktop |
906ED |
9th Generation Intel® Core™ Processor Family |
Desktop |
906ED |
10th Generation Intel® Core™ Processor Family |
Mobile |
A0660 |
10th Generation Intel® Core™ Processor Family |
Mobile |
A0661 |
10th Generation Intel® Core™ Processor Family |
Mobile |
806EC |
10th Generation Intel® Core™ Processor Family |
Desktop |
A0653 |
10th Generation Intel® Core™ Processor Family |
Mobile |
A0655 |
10th Generation Intel® Core™ Processor Family |
Mobile |
A0652 |
Intel® Pentium® Processor Silver Series Intel® Celeron® Processor J Series Intel® Celeron® Processor N Series |
Desktop Mobile Embedded |
706A1 |
Intel® Pentium® Processor Silver Series Intel® Celeron® Processor J Series Intel® Celeron® Processor N Series |
Desktop Mobile Embedded |
706A8 |
10th Generation Intel® Core™ Processor Family |
Mobile |
706E5 |
8th Generation Intel® Core™ Processor Family |
Mobile |
906E9 |
7th Generation Intel® Core™ Processor Family |
Mobile Embedded |
906E9 |
8th Generation Intel® Core™ Processor Family |
Mobile |
806EA |
7th Generation Intel® Core™ Processor Family |
Desktop Embedded |
906E9 |
7th Generation Intel® Core™ Processor Family |
Mobile |
806E9 |
7th Generation Intel® Core™ Processor Family |
Mobile |
806E9 |
Intel® Core™ X-series Processors |
Desktop |
906E9 |
Intel® Xeon® Processor E3 v6 Family |
Server Workstation AMT Server |
906E9 |
7th Generation Intel® Core™ Processor Family |
Mobile |
806E9 |
6th Generation Intel® Core™ Processor Family |
Mobile |
506E3 |
6th Generation Intel® Core™ Processor Family |
Desktop Embedded |
506E3 |
6th Generation Intel® Core™ Processors |
Mobile |
406E3 |
6th Generation Intel® Core™ Processor Family |
Mobile |
406E3 |
Intel® Xeon® Processor E3 v5 Family |
Server Workstation AMT Server |
506E3 |
6th Generation Intel® Core™ Processor Family |
Mobile |
406E3 |
8th Generation Intel® Core™ Processors |
Mobile |
806EB |
8th Generation Intel® Core™ Processors |
Mobile |
806EC |
Install update from vendor's website.
Vulnerable software versionscontainerd: 1.0.0 - 1.7.10
CPE2.3http://github.com/containerd/containerd/security/advisories/GHSA-7ww5-4wqc-m92c
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU48373
Risk: Low
CVSSv3.1: 4.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C]
CVE-ID: CVE-2020-12912
CWE-ID:
CWE-200 - Information exposure
Exploit availability: No
DescriptionThe vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application in the Running Average Power Limit (RAPL) interface. A local user can gain unauthorized access to sensitive information on the system.
MitigationInstall update from vendor's website.
Vulnerable software versionscontainerd: 1.0.0 - 1.7.10
CPE2.3http://github.com/containerd/containerd/security/advisories/GHSA-7ww5-4wqc-m92c
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.