CVE Vulnerabilities

CVE-2020-0586

Improper Initialization

Published: Jun 15, 2020 | Modified: Jul 22, 2020
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Improper initialization in subsystem for Intel(R) SPS versions before SPS_E3_04.01.04.109.0 and SPS_E3_04.08.04.070.0 may allow an authenticated user to potentially enable escalation of privilege and/or denial of service via local access.

Weakness

The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.

Affected Software

Name Vendor Start Version End Version
Server_platform_services Intel sps_e3_04.00.00.000.0 (including) sps_e3_04.01.04.109.0 (excluding)
Server_platform_services Intel sps_e3_04.08.00.000.0 (including) sps_e3_04.08.04.070.0 (excluding)
Server_platform_services Intel sps_e5_04.00.00.000.0 (including) sps_e5_04.01.04.380.0 (excluding)
Server_platform_services Intel sps_soc-a_04.00.00.000.0 (including) sps_soc-a_04.00.04.211.0 (excluding)
Server_platform_services Intel sps_soc-x_04.00.00.000.0 (including) sps_soc-x_04.00.04.128.0 (excluding)

Potential Mitigations

  • Use a language that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid.
  • For example, in Java, if the programmer does not explicitly initialize a variable, then the code could produce a compile-time error (if the variable is local) or automatically initialize the variable to the default value for the variable’s type. In Perl, if explicit initialization is not performed, then a default value of undef is assigned, which is interpreted as 0, false, or an equivalent value depending on the context in which the variable is accessed.

References