Vulnerabilities > CVE-2020-11484 - Insecure Storage of Sensitive Information vulnerability in Intel BMC Firmware 1.06.06/2.47

047910
CVSS 4.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
intel
CWE-922

Summary

NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30, contains a vulnerability in the AMI BMC firmware in which an attacker with administrative privileges can obtain the hash of the BMC/IPMI user password, which may lead to information disclosure.

Vulnerable Configurations

Part Description Count
OS
Intel
3
Hardware
Nvidia
1

Common Weakness Enumeration (CWE)