First published: Wed Feb 17 2021(Updated: )
Use of hard-coded key in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.47 may allow authenticated user to potentially enable information disclosure via local access.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel BMC Firmware | <2.47 | |
Intel HNS2600BPBR | ||
Intel HNS2600BPB24R | ||
Intel HNS2600BPB24R | ||
Intel HNS2600BPBLC | ||
Intel HNS2600BPBLC24 | ||
Intel HNS2600BPBLC24R | ||
Intel HNS2600BPBR | ||
Intel hns2600bpq | ||
Intel HNS2600BPQ24R | ||
Intel HNS2600BPQ24R | ||
Intel HNS2600BPQR | ||
Intel HNS2600BPS Firmware | ||
Intel HNS2600BPS24 | ||
Intel hns2600bps24r | ||
Intel hpchns2600bpsr | ||
Intel Server System R1000WF | ||
Intel Server System r1208wfqysr | ||
Intel Server System R1208WFTYS | ||
Intel Server System R1208WFTYS | ||
Intel Server System R1304WF0YS | ||
Intel Server System R1304WF0YSR | ||
Intel r1304wftys | ||
Intel Server System R1304WFTYSR | ||
Intel Server System R2208WF0ZS | ||
Intel Server System R2208WF0ZSR | ||
Intel R2208WFQZ | ||
Intel R2208WFQZSR | ||
Intel R2208WFTZS | ||
Intel R2208WFTZSR | ||
Intel Server System R2224WFQZS | ||
Intel r2224wftzs | ||
Intel r2224wftzs | ||
Intel R2308WFTZSR | ||
Intel R2308WFTZS | ||
Intel Server System R2312WF0NP | ||
Intel Server System R2312WF0NPR | ||
Intel R2312WFQZS | ||
Intel R2312WFQZS | ||
Intel Server System r2312wftzsr | ||
Intel Server Board S2600BPBR | ||
Intel BBS2600BPQR | ||
Intel S2600BP SR | ||
Intel S2600STB | ||
Intel s2600stq | ||
Intel S2600WF0 | ||
Intel S2600WFQ | ||
Intel S2600WFT |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-12376 is a vulnerability that involves the use of a hard-coded key in the BMC firmware for some Intel Server Boards, Server Systems, and Compute Modules.
CVE-2020-12376 has a severity rating of 5.5 (medium).
CVE-2020-12376 may allow an authenticated user to potentially enable information disclosure via local access to some Intel Server Boards, Server Systems, and Compute Modules.
To fix CVE-2020-12376, you need to update the BMC firmware to version 2.47 or higher.
You can find more information about CVE-2020-12376 on the Intel Security Advisory page at the following link: [link](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00434.html)