← Vulnerability feed

Vulnerability record · CVE-2020-8755 · published 12 November 2020

CVE-2020-8755: Intel converged security and management engine race condition vulnerability

Intel · Converged Security And Management Engine

Race condition in subsystem for Intel(R) CSME versions before 12.0.70 and 14.0.45, Intel(R) SPS versions before E5_04.01.04.400 and E3_05.01.04.200 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

6.4 CVSS 3.1 Medium EPSS 0.28% · top 81.8% CWE-362 · Race condition
6.4CVSS 3.1 base score, v2 4.4
0.28%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Race condition in subsystem for Intel(R) CSME versions before 12.0.70 and 14.0.45, Intel(R) SPS versions before E5_04.01.04.400 and E3_05.01.04.200 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-8755 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2022-36348Intel server platform services vulnerabilityActive debug code in some Intel (R) SPS firmware before version SPS_E5_04.04.04.300.0 may allow an authenticated user to potentially enable escalatio…EPSS 0.20%7.8CVE-2020-8744Intel converged security and management engine vulnerabilityImproper initialization in subsystem for Intel(R) CSME versions before12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE versions before 4…EPSS 0.36%7.8CVE-2020-0586Intel server platform services vulnerabilityImproper initialization in subsystem for Intel(R) SPS versions before SPS_E3_04.01.04.109.0 and SPS_E3_04.08.04.070.0 may allow an authenticated user…EPSS 0.37%7.8CVE-2019-0091Intel converged security and management engine code injection vulnerabilityCode injection vulnerability in installer for Intel(R) CSME before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 and Intel(R) TXE 3.1.65, 4.0.15 may …EPSS 0.52%7.1CVE-2019-0090Intel converged security and management engine vulnerabilityInsufficient access control vulnerability in subsystem for Intel(R) CSME before versions 11.x, 12.0.35 Intel(R) TXE 3.x, 4.x, Intel(R) Server Platfor…EPSS 0.36%6.8CVE-2020-8705Intel converged security and manageability engine insecure default initialization vulnerabilityInsecure default initialization of resource in Intel(R) Boot Guard in Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13…EPSS 0.50%6.7CVE-2020-24509Intel server platform services vulnerabilityInsufficient control flow management in subsystem in Intel(R) SPS versions before SPS_E3_05.01.04.300.0, SPS_SoC-A_05.00.03.091.0, SPS_E5_04.04.04.02…EPSS 0.25%6.7CVE-2019-0089Intel server platform services vulnerabilityImproper data sanitization vulnerability in subsystem in Intel(R) SPS before versions SPS_E5_04.00.04.381.0, SPS_E3_04.01.04.054.0, SPS_SoC-A_04.00.0…EPSS 0.38%

Source: NIST National Vulnerability Database (record CVE-2020-8755), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.