#VU54204 Observable discrepancy in Intel products - CVE-2020-24512 

 

#VU54204 Observable discrepancy in Intel products - CVE-2020-24512

Published: June 17, 2021


Vulnerability identifier: #VU54204
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2020-24512
CWE-ID: CWE-203
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
Legacy Intel Core Processors
Intel Xeon E Processors
Intel Core X-series Processors
Intel Atom Processor Z Series
Intel Celeron Processor J Series
Intel Celeron Processor N Series
Intel Atom Processor E3800 Product Family
Legacy Intel Pentium Processors
Legacy Intel Celeron Processors
3rd Generation Intel Core Processors
Intel Pentium Processors
Intel Celeron Processors
4th Generation Intel Core Processor Family
1th Generation Intel Core Processor Family
2nd Generation Intel Core Processor Family
3rd Intel Xeon E processor family
5th Generation Intel Core Processor Family
Intel Atom Processors
Intel Atom Processor X Series
Intel Atom Processor C Series
6th Generation Intel Core Processors
Intel Xeon D Processors
Intel Xeon W Processors
2nd Generation Intel Xeon Scalable Processors
Intel Core X-series Processor
3rd Generation Intel Xeon Scalable Processors
Intel Atom Processor A Series
Intel Puma 7 Family
Intel Pentium Processor Silver Series
10th Generation Intel Core Processors
Intel Core Processors with Intel Hybrid Technology
11th Generation Intel Core Processors
8th Generation Intel Core Processors
7th Generation Intel Core Processors
Intel Pentium Gold Processor Series
Intel Celeron Processor 5000 Series
Intel Celeron Processor G Series
Intel Pentium Processor J Series
Intel Pentium Processor N Series
Intel Xeon Scalable Processors
Intel Atom Processor E3900 Series
9th Generation Intel Core Processors
Software vendor:
Intel

Description

The vulnerability allows a local user to gain access to potentially sensitive information.

The vulnerability exists due to observable timing discrepancy. A local user can gain unauthorized access to sensitive information on the system.


Remediation

Install updates from vendor's website.

External links