Improper Input Validation in Intel Server System M70KLP BIOS Firmware
CVE-2022-24379

6.7MEDIUM

Key Information:

Vendor
Intel
Vendor
CVE Published:
14 November 2023

Summary

Improper input validation exists in the BIOS firmware of the Intel Server System M70KLP Family prior to version 01.04.0029, which may enable a privileged user to escalate privileges via local access. This vulnerability can pose a significant risk by allowing attackers to manipulate the system's normal processes, potentially leading to unauthorized access and control over the affected systems.

Affected Version(s)

Intel(R) Server System M70KLP Family BIOS firmware before version 01.04.0029

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.