Insufficient Session Validation in Intel Baseboard Management Controller Firmware
CVE-2019-11168

9.1CRITICAL

Key Information:

Vendor
Intel
Vendor
CVE Published:
14 November 2019

Summary

The Intel Baseboard Management Controller firmware has shown weaknesses in session validation processes. An unauthenticated user could exploit these vulnerabilities to gain unauthorized access, potentially leading to information disclosure or a denial of service situation. This threat emphasizes the importance of robust session management practices to safeguard sensitive information and ensure system integrity.

Affected Version(s)

Intel(R) BMC See provided reference

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.