Vulnerabilities > Intel > Baseboard Management Controller Firmware

DATE CVE VULNERABILITY TITLE RISK
2023-02-16 CVE-2022-29493 Improper Handling of Exceptional Conditions vulnerability in Intel Baseboard Management Controller Firmware
Uncaught exception in webserver for the Integrated BMC in some Intel(R) platforms before versions 2.86, 2.09 and 2.78 may allow a privileged user to potentially enable denial of service via network access.
network
low complexity
intel CWE-755
4.9
2021-06-09 CVE-2020-24473 Out-of-bounds Write vulnerability in Intel Baseboard Management Controller Firmware 2.09/2.18
Out of bounds write in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.48.ce3e3bd2 may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-787
7.8
2021-06-09 CVE-2020-24474 Classic Buffer Overflow vulnerability in Intel Baseboard Management Controller Firmware 2.09/2.18
Buffer overflow in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.48.ce3e3bd2 may allow an authenticated user to potentially enable escalation of privilege via adjacent access.
low complexity
intel CWE-120
8.0
2021-06-09 CVE-2020-24475 Improper Initialization vulnerability in Intel Baseboard Management Controller Firmware 2.09/2.18
Improper initialization in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.48.ce3e3bd2 may allow an authenticated user to potentially enable denial of service via local access.
local
low complexity
intel CWE-665
5.5
2019-11-14 CVE-2019-11182 Out-of-bounds Write vulnerability in Intel Baseboard Management Controller Firmware 2.09
Memory corruption in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable denial of service via network access.
network
low complexity
intel CWE-787
7.5
2019-11-14 CVE-2019-11181 Out-of-bounds Read vulnerability in Intel Baseboard Management Controller Firmware 2.09
Out of bound read in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable escalation of privilege via network access.
local
low complexity
intel CWE-125
7.8
2019-11-14 CVE-2019-11180 Improper Input Validation vulnerability in Intel Baseboard Management Controller Firmware 2.09
Insufficient input validation in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable denial of service via network access.
network
low complexity
intel CWE-20
7.5
2019-11-14 CVE-2019-11179 Improper Input Validation vulnerability in Intel Baseboard Management Controller Firmware 2.09
Insufficient input validation in Intel(R) Baseboard Management Controller firmware may allow an authenticated user to potentially enable information disclosure via network access.
network
low complexity
intel CWE-20
6.5
2019-11-14 CVE-2019-11178 Classic Buffer Overflow vulnerability in Intel Baseboard Management Controller Firmware 2.09
Stack overflow in Intel(R) Baseboard Management Controller firmware may allow an authenticated user to potentially enable information disclosure and/or denial of service via network access.
network
low complexity
intel CWE-120
8.1
2019-11-14 CVE-2019-11177 Improper Handling of Exceptional Conditions vulnerability in Intel Baseboard Management Controller Firmware 2.09
Unhandled exception in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable denial of service via network access.
network
low complexity
intel CWE-755
7.5