{"api_version":"1","generated_at":"2026-07-23T12:52:09+00:00","cve":"CVE-2020-12339","urls":{"html":"https://cve.report/CVE-2020-12339","api":"https://cve.report/api/cve/CVE-2020-12339.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-12339","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-12339"},"summary":{"title":"CVE-2020-12339","description":"Insufficient control flow management in the API for the Intel(R) Collaboration Suite for WebRTC before version 4.3.1 may allow an authenticated user to potentially enable escalation of privilege via network access.","state":"PUBLIC","assigner":"secure@intel.com","published_at":"2021-02-17 14:15:00","updated_at":"2021-02-22 18:02:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00425.html","name":"https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00425.html","refsource":"MISC","tags":["Vendor Advisory"],"title":"INTEL-SA-00425","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-12339","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-12339","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"12339","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"intel","cpe5":"collaboration_suite","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"webrtc","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"12339","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"intel","cpe5":"collaboration_suite","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"webrtc","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2020-12339","ASSIGNER":"secure@intel.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"n/a","product":{"product_data":[{"product_name":"Intel(R) Collaboration Suite for WebRTC","version":{"version_data":[{"version_value":"before version 4.3.1"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"escalation of privilege"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00425.html","url":"https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00425.html"}]},"description":{"description_data":[{"lang":"eng","value":"Insufficient control flow management in the API for the Intel(R) Collaboration Suite for WebRTC before version 4.3.1 may allow an authenticated user to potentially enable escalation of privilege via network access."}]}},"nvd":{"publishedDate":"2021-02-17 14:15:00","lastModifiedDate":"2021-02-22 18:02:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.5},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:intel:collaboration_suite:*:*:*:*:*:webrtc:*:*","versionEndExcluding":"4.3.1","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"12339","Ordinal":"173499","Title":"CVE-2020-12339","CVE":"CVE-2020-12339","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"12339","Ordinal":"1","NoteData":"Insufficient control flow management in the API for the Intel(R) Collaboration Suite for WebRTC before version 4.3.1 may allow an authenticated user to potentially enable escalation of privilege via network access.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"12339","Ordinal":"2","NoteData":"2021-02-17","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"12339","Ordinal":"3","NoteData":"2021-02-17","Type":"Other","Title":"Modified"}]}}}