« Volver al listado

CVE-2020-24491

Estado: ModificadaMedia (4.4)—

Debug message containing addresses of memory transactions in some Intel(R) 10th Generation Core Processors supporting SGX may allow a privileged user to potentially enable information disclosure via local access.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-24491",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 1.9,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:M/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.4,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.4,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 0.8
      }
    ]
  },
  "affected": [
    {
      "source": "secure@intel.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "Intel(R) 10th Generation Core Processors supporting SGX",
          "versions": [
            {
              "status": "affected",
              "version": "See references"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-02-17T14:15:17.653",
  "references": [
    {
      "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00455.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "secure@intel.com"
    },
    {
      "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00455.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Debug message containing addresses of memory transactions in some Intel(R) 10th Generation Core Processors supporting SGX may allow a privileged user to potentially enable information disclosure via local access."
    },
    {
      "lang": "es",
      "value": "El mensaje de depuración que contiene direcciones de transacciones de memoria en algunos Intel® 10th Generation Core Processors que admiten SGX puede permitir a un usuario privilegiado habilitar potencialmente una divulgación de información por medio de un acceso local"
    }
  ],
  "lastModified": "2026-06-17T03:05:40.230",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:intel:core_i3:1000g1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "639301E7-B11E-47AA-B02B-4627BCBCBD94"
            },
            {
              "criteria": "cpe:2.3:h:intel:core_i3:1000g4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1ECAFBEF-B249-4949-96C5-2A1B7F8A45D7"
            },
            {
              "criteria": "cpe:2.3:h:intel:core_i3:1005g1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "473D9714-BDB6-49E8-9236-B28FC4D9D7FD"
            },
            {
              "criteria": "cpe:2.3:h:intel:core_i5:1030g4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BDF03953-872A-4BF5-8D6D-96F9691805BF"
            },
            {
              "criteria": "cpe:2.3:h:intel:core_i5:1030g7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EBA20908-7371-4161-BE1A-CD167F5022B0"
            },
            {
              "criteria": "cpe:2.3:h:intel:core_i5:1035g1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "873D7ACF-B2C0-4F09-9736-C85BDA8602CA"
            },
            {
              "criteria": "cpe:2.3:h:intel:core_i5:1035g4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8D4A7E1D-FB53-4093-9E6E-6161415A98BB"
            },
            {
              "criteria": "cpe:2.3:h:intel:core_i5:1035g7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "805EAA7E-0A1D-43D0-B3FB-80DBF9018008"
            },
            {
              "criteria": "cpe:2.3:h:intel:core_i7:1060g7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "863A74E1-7FED-47CE-81DD-74EF3174B906"
            },
            {
              "criteria": "cpe:2.3:h:intel:core_i7:1065g7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "315890AF-DC58-445A-887B-F497BD62392D"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secure@intel.com"
}