Improper Input Validation in Intel Server Board BMC Firmware
CVE-2023-25175

6.1MEDIUM

Key Information:

Vendor
Intel
Vendor
CVE Published:
10 May 2023

Summary

An improper input validation vulnerability exists in the Intel Server Board BMC firmware, which impacts versions prior to 2.90. This flaw may be exploited by a privileged user to facilitate information disclosure when accessing the system locally. It is crucial for organizations using affected firmware versions to assess their security posture and apply relevant updates as recommended in official advisories.

Affected Version(s)

Intel(R) Server Board BMC firmware before version 2.90

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.