{"id":"CVE-2020-8670","title":"Race condition in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.","summary":"Race condition in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.","severity":"medium","cvss":6.4,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-362"],"vendor":"netapp","product":"cloud_backup","affected":["bios","simatic_field_pg_m6_firmware","simatic_ipc427e_firmware","simatic_ipc477e_firmware","simatic_ipc477e_pro_firmware","simatic_ipc527g_firmware","simatic_ipc547g_firmware","simatic_ipc627e_firmware < 25.02.10","simatic_ipc647e_firmware < 25.02.10","simatic_ipc677e_firmware < 25.02.10","simatic_ipc847e_firmware < 25.02.10","simatic_itp1000_firmware","cloud_backup","aff_bios","fas_bios","hci_compute_node_bios","hci_storage_node_bios","solidfire_bios"],"patched":["simatic_ipc627e_firmware 25.02.10","simatic_ipc647e_firmware 25.02.10","simatic_ipc677e_firmware 25.02.10","simatic_ipc847e_firmware 25.02.10"],"published":"2021-06-09","updated":"2026-10-08","sourceUpdated":"2026-10-08T21:17:31.670","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2020-8670","references":[{"url":"https://cert-portal.siemens.com/productcert/pdf/ssa-309571.pdf","label":"secure@intel.com"},{"url":"https://security.netapp.com/advisory/ntap-20210702-0002/","label":"secure@intel.com"},{"url":"https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00463.html","label":"secure@intel.com"},{"url":"https://cert-portal.siemens.com/productcert/pdf/ssa-309571.pdf","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20210702-0002/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00463.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.00268,"epssPercentile":0.17312,"ingestedAt":"2026-10-08T22:11:53.735Z","slug":"CVE-2020-8670","body":"## Overview\n\nRace condition in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.\n\n## Affected\n\n- `bios`\n- `simatic_field_pg_m6_firmware`\n- `simatic_ipc427e_firmware`\n- `simatic_ipc477e_firmware`\n- `simatic_ipc477e_pro_firmware`\n- `simatic_ipc527g_firmware`\n- `simatic_ipc547g_firmware`\n- `simatic_ipc627e_firmware < 25.02.10`\n- `simatic_ipc647e_firmware < 25.02.10`\n- `simatic_ipc677e_firmware < 25.02.10`\n- `simatic_ipc847e_firmware < 25.02.10`\n- `simatic_itp1000_firmware`\n- `cloud_backup`\n- `aff_bios`\n- `fas_bios`\n- `hci_compute_node_bios`\n- `hci_storage_node_bios`\n- `solidfire_bios`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `simatic_ipc627e_firmware 25.02.10`\n- `simatic_ipc647e_firmware 25.02.10`\n- `simatic_ipc677e_firmware 25.02.10`\n- `simatic_ipc847e_firmware 25.02.10`","depth":"sunlit","depthScore":35,"depthScoreParts":{"impact":35.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}