First published: Fri Feb 19 2021(Updated: )
Buffer overflow in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.47 may allow a privileged user to potentially enable escalation of privilege via local access.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel BMC Firmware | <2.47 | |
Intel HNS2600BPBR | ||
Intel HNS2600BPB24R | ||
Intel HNS2600BPB24R | ||
Intel HNS2600BPBLC | ||
Intel HNS2600BPBLC24 | ||
Intel HNS2600BPBLC24R | ||
Intel HNS2600BPBR | ||
Intel HNS2600WPQ | ||
Intel HNS2600BPQ24R | ||
Intel HNS2600BPQ24R | ||
Intel HNS2600BPQR | ||
Intel HNS2600BPS Firmware | ||
Intel HNS2600BPS24 | ||
Intel hns2600bps24r | ||
Intel hpchns2600bpsr | ||
Intel Server System R1000WF | ||
Intel Server System r1208wfqysr | ||
Intel Server System R1208WFTYS | ||
Intel Server System R1208WFTYS | ||
Intel Server System R1304WF0YS | ||
Intel Server System R1304WF0YSR | ||
Intel r1304wftys | ||
Intel Server System R1304WFTYSR | ||
Intel Server System R2208WF0ZS | ||
Intel Server System R2208WF0ZSR | ||
Intel R2208WFQZ | ||
Intel R2208WFQZSR | ||
Intel R2208WFTZS | ||
Intel R2208WFTZSR | ||
Intel Server System R2224WFQZS | ||
Intel r2224wftzs | ||
Intel r2224wftzs | ||
Intel R2308WFTZSR | ||
Intel R2308WFTZS | ||
Intel Server System R2312WF0NP | ||
Intel Server System R2312WF0NPR | ||
Intel R2312WFQZS | ||
Intel R2312WFQZS | ||
Intel Server System r2312wftzsr | ||
Intel Server Board S2600BPBR | ||
Intel BBS2600BPQR | ||
Intel S2600BP SR | ||
Intel S2600STB | ||
Intel s2600stq | ||
Intel S2600WF0 | ||
Intel S2600WFQ | ||
Intel S2600WFT |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-12374 is a buffer overflow vulnerability in the BMC firmware for some Intel Server Boards, Server Systems, and Compute Modules.
The severity of CVE-2020-12374 is medium with a CVSS score of 6.7.
A privileged user can potentially enable escalation of privilege via local access.
BMC firmware versions before 2.47 on some Intel Server Boards, Server Systems, and Compute Modules are affected by CVE-2020-12374.
You can find more information about CVE-2020-12374 on the Intel Security Center advisory page: [Link](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00434.html)