Improper Input Validation in Intel Server Firmware
CVE-2025-20034

5.6MEDIUM

Key Information:

Vendor

Intel

Vendor
CVE Published:
13 May 2025

What is CVE-2025-20034?

The BackupBiosUpdate UEFI firmware SmiVariable driver in Intel Server D50DNP and M50FCP boards prior to version R01.02.0003 exhibits improper input validation, which may allow privileged users to exploit the vulnerability for information disclosure through local access. It is crucial for affected users to update their firmware to the latest version to mitigate potential security risks. For detailed information, refer to Intel's advisory.

Affected Version(s)

Intel(R) Server D50DNP and M50FCP boards before version R01.02.0003

References

CVSS V4

Score:
5.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.