First published: Thu Nov 14 2019(Updated: )
Heap corruption in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable information disclosure, escalation of privilege and/or denial of service via network access.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel Baseboard Management Controller Firmware | <2.18 | |
Intel BBS2600BPB | ||
Intel Server Board S2600BPBR | ||
Intel BBS2600BPQR | ||
Intel BBS2600BPQR | ||
Intel BBS2600BPS | ||
Intel BBS2600BPS | ||
Intel BBS2600STB | ||
Intel BBS2600STBR | ||
Intel BBS2600STQR | ||
Intel BBS2600STQR | ||
Intel HNS2600BPBR | ||
Intel HNS2600BPB24R | ||
Intel HNS2600BPB24R | ||
Intel HNS2600BPB24R | ||
Intel HNS2600BPBLC | ||
Intel HNS2600BPBLC24 | ||
Intel HNS2600BPBLC24R | ||
Intel HNS2600BPBLCR | ||
Intel HNS2600BPBR | ||
Intel HNS2600BPBRX | ||
Intel HNS2600WPQ | ||
Intel HNS2600BPQ24R | ||
Intel HNS2600BPQ24R | ||
Intel HNS2600BPQR | ||
Intel HNS2600BPS Firmware | ||
Intel HNS2600BPS24R | ||
Intel HNS2600BPS24R | ||
Intel hpchns2600bpsr | ||
Intel HNS2600 Series | ||
Intel HNS2600BPQR | ||
Intel HNS2600 Series | ||
Intel HPCR1208WFQYSR | ||
Intel HPCR1208WFTYSR | ||
Intel Server System R1304WF0YSR | ||
Intel Server System R1304WFTYSR | ||
Intel hpcr2208wf0zsr | ||
Intel Server System R2208WFQZSR | ||
Intel hpcr2208wfqzsr | ||
Intel hpcr2208wftzsrx | ||
Intel hpcr2224wftzsr | ||
Intel R2308WFTZSR | ||
Intel Server System R2312WF0NPR | ||
Intel hpcr2312wftzsr | ||
Intel HPCR1208WFQYSR | ||
Intel Server System R1208WFTYS | ||
Intel Server System R1208WFTYS | ||
Intel Server System R1304WF0YS | ||
Intel Server System R1304WF0YSR | ||
Intel Server System R1304WFTYS | ||
Intel Server System R1304WFTYSR | ||
Intel Server System R2208WF0ZS | ||
Intel Server System R2208WF0ZSR | ||
Intel R2208WFQZ | ||
Intel Server System R2208WFQZSR | ||
Intel R2208WFTZS | ||
Intel R2208WFTZS | ||
Intel R2208WFTZSR | ||
Intel Server System R2224WFQZS | ||
Intel R2224WFTZS | ||
Intel r2224wftzs | ||
Intel Server System R2308WFTZS | ||
Intel Server System R2308WFTZSR | ||
Intel Server System R2312WF0NP | ||
Intel Server System R2312WF0NPR | ||
Intel Server System R2312WFQZS | ||
Intel R2312WFQZS | ||
Intel Server System r2312wftzsr | ||
Intel Server Board S2600STB | ||
Intel S2600STBR Firmware | ||
Intel S2600STQ | ||
Intel BBS2600STQR | ||
Intel Server Board S2600WF0 | ||
Intel Server Board S2600WF0R | ||
Intel Server Board S2600WFQ | ||
Intel S2600WFQR Firmware | ||
Intel Server Board S2600WFT | ||
Intel S2600WFTR Firmware | ||
Intel Server System S9200WK | ||
Intel s9232wk2hac | ||
Intel SSD Pro 5400s | ||
Intel Server System S9200WK | ||
Intel SSD 540s | ||
Intel SSD Pro 5400s | ||
Intel Server System S9256WK1HLC |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-11171 is high due to potential information disclosure, escalation of privilege, and denial of service.
To fix CVE-2019-11171, update your Intel Baseboard Management Controller firmware to version 2.18 or later.
CVE-2019-11171 can facilitate information disclosure, escalation of privileges, and denial of service attacks.
CVE-2019-11171 affects Intel Baseboard Management Controller firmware versions prior to 2.18.
Yes, CVE-2019-11171 can be exploited remotely via network access.