{"id":"CVE-2020-12359","title":"Insufficient control flow management in the firmware for some Intel(R) Processors may allow an unauthenticated user to potentially enable escalation of privilege via physical access.","summary":"Insufficient control flow management in the firmware for some Intel(R) Processors may allow an unauthenticated user to potentially enable escalation of privilege via physical access.","severity":"medium","cvss":6.8,"cvssVector":"CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-691"],"vendor":"netapp","product":"cloud_backup","affected":["bios","cloud_backup","aff_bios","e-series_bios","fas_bios","hci_compute_node_bios","hci_storage_node_bios","solidfire_bios"],"published":"2021-06-09","updated":"2026-10-07","sourceUpdated":"2026-10-07T17:16:41.420","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2020-12359","references":[{"url":"https://security.netapp.com/advisory/ntap-20210702-0002/","label":"secure@intel.com"},{"url":"https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00463.html","label":"secure@intel.com"},{"url":"https://security.netapp.com/advisory/ntap-20210702-0002/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00463.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-10-07T16:22:10.685808Z"},"epss":0.00318,"epssPercentile":0.22691,"ingestedAt":"2026-10-07T16:38:22.238Z","slug":"CVE-2020-12359","body":"## Overview\n\nInsufficient control flow management in the firmware for some Intel(R) Processors may allow an unauthenticated user to potentially enable escalation of privilege via physical access.\n\n## Affected\n\n- `bios`\n- `cloud_backup`\n- `aff_bios`\n- `e-series_bios`\n- `fas_bios`\n- `hci_compute_node_bios`\n- `hci_storage_node_bios`\n- `solidfire_bios`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":37,"depthScoreParts":{"impact":37.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}