A potential security vulnerability in Intel® Solid State Drive (SSD) products may allow information disclosure.** **Intel is releasing firmware updates to mitigate this potential vulnerability.
CVE ID: CVE-2020-0527
Description: Insufficient control flow management in firmware for some Intel® Data Center SSDs may allow a privileged user to potentially enable information disclosure via local access.
CVSS Base Score: 7.9 High
CVSS Vector: CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
Intel® SSD D3-S4510 Series
Intel® SSD DC P4510 Series
Intel® SSD DC P4610 Series
Intel® SSD DC P4618 Series
Intel® SSD DC P4511 Series
Intel recommends updating Intel® SSD products to the latest firmware (see table).__
Product Names
|
Mitigated version
—|—
Intel® SSD D3-S4510 Series M.2 FF
|
FW: XC311120
Intel® SSD DC P4510 Series (U.2 only)
Intel® SSD DC P4510 Series OPAL
Intel® SSD DC P4610 Series
Intel® SSD DC P4610 Series OPAL
Intel® SSD DC P4618 Series
|
FW: VDV10170
Intel® SSD DC P4511 Series (m.2 only)
|
FW: VCV10370
Updates are available for download at this location:
<https://downloadcenter.intel.com/download/29428/Intel-Memory-and-Storage-Tool?product=35125>
The issue was found internally by Intel.
Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available.