First published: Wed Sep 12 2018(Updated: )
Privilege escalation in Intel Baseboard Management Controller (BMC) firmware before version 1.43.91f76955 may allow an unprivileged user to potentially execute arbitrary code or perform denial of service over the network.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel BMC Firmware | <1.43.91f76955 | |
Intel BBS2600BPB | ||
Intel BBS2600BPQR | ||
Intel bbs2600bps | ||
Intel BBS2600STB | ||
Intel BBS2600STQR | ||
Intel HNS2600BPBR | ||
Intel HNS2600BPB24R | ||
Intel HNS2600BPBLC | ||
Intel HNS2600BPBLC24 | ||
Intel hns2600bpq | ||
Intel HNS2600BPQ24R | ||
Intel HNS2600BPS Firmware | ||
Intel HNS2600BPS24 | ||
Intel Server System R1208WFTYS | ||
Intel Server System R1304WF0YS | ||
Intel r1304wftys | ||
Intel Server System R2208WF0ZS | ||
Intel R2208WFQZ | ||
Intel R2208WFTZS | ||
Intel Server System R2224WFQZS | ||
Intel r2224wftzs | ||
Intel R2308WFTZSR | ||
Intel Server System R2312WF0NP | ||
Intel R2312WFQZS | ||
Intel R2312WFQZS | ||
Intel S2600STB | ||
Intel s2600stq | ||
Intel S2600WF | ||
Intel S2600WFQ | ||
Intel S2600WFT |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-12171 is a vulnerability in Intel Baseboard Management Controller (BMC) firmware that allows an unprivileged user to potentially execute arbitrary code or perform denial of service over the network.
The severity of CVE-2018-12171 is critical, with a CVSS score of 9.8.
Intel Baseboard Management Controller (BMC) firmware version up to and excluding 1.43.91f76955 is affected by CVE-2018-12171.
To fix CVE-2018-12171, upgrade the Intel Baseboard Management Controller (BMC) firmware to version 1.43.91f76955 or later.
More information about CVE-2018-12171 can be found at the following link: [Intel Advisory for CVE-2018-12171](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00149.html).