{"id":"CVE-2020-24511","title":"Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.","summary":"Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","cwe":["CWE-668"],"vendor":"intel","product":"microcode","affected":["microcode < 20210608","debian_linux = 10.0","fas/aff_bios","hci_compute_node_bios","solidfire_bios"],"patched":["microcode 20210608"],"published":"2021-06-09","updated":"2026-10-08","sourceUpdated":"2026-10-08T21:17:25.567","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2020-24511","references":[{"url":"https://cert-portal.siemens.com/productcert/pdf/ssa-309571.pdf","label":"secure@intel.com"},{"url":"https://lists.debian.org/debian-lts-announce/2021/07/msg00022.html","label":"secure@intel.com"},{"url":"https://security.netapp.com/advisory/ntap-20210611-0005/","label":"secure@intel.com"},{"url":"https://www.debian.org/security/2021/dsa-4934","label":"secure@intel.com"},{"url":"https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00464.html","label":"secure@intel.com"},{"url":"https://cert-portal.siemens.com/productcert/pdf/ssa-309571.pdf","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2021/07/msg00022.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20210611-0005/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.debian.org/security/2021/dsa-4934","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00464.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.00399,"epssPercentile":0.32007,"ingestedAt":"2026-10-08T22:11:53.734Z","slug":"CVE-2020-24511","body":"## Overview\n\nImproper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.\n\n## Affected\n\n- `microcode < 20210608`\n- `debian_linux = 10.0`\n- `fas/aff_bios`\n- `hci_compute_node_bios`\n- `solidfire_bios`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `microcode 20210608`","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}