Potential Information Disclosure Vulnerability in OpenBMC Firmware for Intel Server Platforms
CVE-2023-49144

6.7MEDIUM

Key Information:

Vendor

OpenBMC

Vendor
CVE Published:
14 August 2024

What is CVE-2023-49144?

Out of bounds read in OpenBMC Firmware for some Intel(R) Server Platforms before versions egs-1.15-0, bhs-0.27 may allow a privileged user to potentially enable information disclosure via local access.

Affected Version(s)

Intel(R) Server Platforms before versions egs-1.15-0, bhs-0.27

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.