First published: Wed Sep 12 2018(Updated: )
Privilege escalation in Intel Baseboard Management Controller (BMC) firmware before version 1.43.91f76955 may allow an unprivileged user to potentially execute arbitrary code or perform denial of service over the network.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel Bmc Firmware | <1.43.91f76955 | |
Intel Bbs2600bpb | ||
Intel Bbs2600bpq | ||
Intel Bbs2600bps | ||
Intel Bbs2600stb | ||
Intel Bbs2600stq | ||
Intel Hns2600bpb | ||
Intel Hns2600bpb24 | ||
Intel Hns2600bpblc | ||
Intel Hns2600bpblc24 | ||
Intel Hns2600bpq | ||
Intel Hns2600bpq24 | ||
Intel Hns2600bps | ||
Intel Hns2600bps24 | ||
Intel R1208wftys | ||
Intel R1304wf0ys | ||
Intel R1304wftys | ||
Intel R2208wf0zs | ||
Intel R2208wfqzs | ||
Intel R2208wftzs | ||
Intel R2224wfqzs | ||
Intel R2224wftzs | ||
Intel R2308wftzs | ||
Intel R2312wf0np | ||
Intel R2312wfqzs | ||
Intel R2312wftzs | ||
Intel S2600stb | ||
Intel S2600stq | ||
Intel S2600wfo | ||
Intel S2600wfq | ||
Intel S2600wft |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-12171 is a vulnerability in Intel Baseboard Management Controller (BMC) firmware that allows an unprivileged user to potentially execute arbitrary code or perform denial of service over the network.
The severity of CVE-2018-12171 is critical, with a CVSS score of 9.8.
Intel Baseboard Management Controller (BMC) firmware version up to and excluding 1.43.91f76955 is affected by CVE-2018-12171.
To fix CVE-2018-12171, upgrade the Intel Baseboard Management Controller (BMC) firmware to version 1.43.91f76955 or later.
More information about CVE-2018-12171 can be found at the following link: [Intel Advisory for CVE-2018-12171](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00149.html).