CVE-2019-11171: Critical severity intel baseboard management controller firmware vulnerability

Published Nov 14, 2019
·
Updated

Heap corruption in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable information disclosure, escalation of privilege and/or denial of service via network access.

Affected Software

85 affected components
Intel Baseboard Management Controller firmware<2.18
Intel Bbs2600bpb
Intel Bbs2600bpbr
Intel Bbs2600bpq
Intel Bbs2600bpqr
Intel Bbs2600bps
Intel Bbs2600bpsr
Intel Bbs2600stb
Intel Bbs2600stbr
Intel Bbs2600stq
Intel Bbs2600stqr
Intel Hns2600bpb
Intel Hns2600bpb24
Intel Hns2600bpb24r
Intel Hns2600bpb24rx
Intel Hns2600bpblc
Intel Hns2600bpblc24
Intel Hns2600bpblc24r
Intel Hns2600bpblcr
Intel Hns2600bpbr
Intel Hns2600bpbrx
Intel Hns2600bpq
Intel Hns2600bpq24
Intel Hns2600bpq24r
Intel Hns2600bpqr
Intel Hns2600bps
Intel Hns2600bps24
Intel Hns2600bps24r
Intel Hns2600bpsr
Intel Hpchns2600bpbr
Intel Hpchns2600bpqr
Intel Hpchns2600bpsr
Intel Hpcr1208wfqysr
Intel Hpcr1208wftysr
Intel Hpcr1304wf0ysr
Intel Hpcr1304wftysr
Intel Hpcr2208wf0zsr
Intel Hpcr2208wfqzsr
Intel Hpcr2208wftzsr
Intel Hpcr2208wftzsrx
Intel Hpcr2224wftzsr
Intel Hpcr2308wftzsr
Intel Hpcr2312wf0npr
Intel Hpcr2312wftzsr
Intel R1208wfqysr
Intel R1208wftys
Intel R1208wftysr
Intel R1304wf0ys
Intel R1304wf0ysr
Intel R1304wftys
Intel R1304wftysr
Intel R2208wf0zs
Intel R2208wf0zsr
Intel R2208wfqzs
Intel R2208wfqzsr
Intel R2208wftzs
Intel R2208wftzsr
Intel R2208wftzsrx
Intel R2224wfqzs
Intel R2224wftzs
Intel R2224wftzsr
Intel R2308wftzs
Intel R2308wftzsr
Intel R2312wf0np
Intel R2312wf0npr
Intel R2312wfqzs
Intel R2312wftzs
Intel R2312wftzsr
Intel S2600stb
Intel S2600stbr
Intel S2600stq
Intel S2600stqr
Intel S2600wf0
Intel S2600wf0r
Intel S2600wfq
Intel S2600wfqr
Intel S2600wft
Intel S2600wftr
Intel S9232wk1hlc
Intel S9232wk2hac
Intel S9232wk2hlc
Intel S9248wk1hlc
Intel S9248wk2hac
Intel S9248wk2hlc
Intel S9256wk1hlc

Event History

Nov 14, 2019
CVE Published
via MITRE·04:36 PM
Data Sourced
via MITRE·04:36 PM
DescriptionWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2019-11171?

The severity of CVE-2019-11171 is high due to potential information disclosure, escalation of privilege, and denial of service.

2

How do I fix CVE-2019-11171?

To fix CVE-2019-11171, update your Intel Baseboard Management Controller firmware to version 2.18 or later.

3

What types of attacks can CVE-2019-11171 facilitate?

CVE-2019-11171 can facilitate information disclosure, escalation of privileges, and denial of service attacks.

4

Which Intel products are affected by CVE-2019-11171?

CVE-2019-11171 affects Intel Baseboard Management Controller firmware versions prior to 2.18.

5

Is CVE-2019-11171 exploited remotely?

Yes, CVE-2019-11171 can be exploited remotely via network access.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203