Insufficient Input Validation in Intel Baseboard Management Controller Firmware
CVE-2019-11179

6.5MEDIUM

Key Information:

Vendor
Intel
Vendor
CVE Published:
14 November 2019

Summary

A vulnerability exists in Intel's Baseboard Management Controller firmware due to insufficient input validation. An authenticated user could exploit this flaw to potentially disclose sensitive information through network access. This vulnerability emphasizes the need for robust security measures within firmware to safeguard against unauthorized data access. For more detailed insights, visit the Intel security advisory.

Affected Version(s)

Intel(R) BMC See provided reference

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.