CWE
120 119
Advisory Published
Updated

CVE-2020-24474: Buffer Overflow

First published: Wed Jun 09 2021(Updated: )

Buffer overflow in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.48.ce3e3bd2 may allow an authenticated user to potentially enable escalation of privilege via adjacent access.

Credit: secure@intel.com

Affected SoftwareAffected VersionHow to fix
<2.48.ce3e3bd2
Intel Compute Module Hns2600bpb24r
Intel Compute Module Hns2600bpbr
Intel Compute Module Hns2600bpq24r
Intel Compute Module Hns2600bpqr
Intel Compute Module Hns2600bps24r
Intel Compute Module Hns2600bpsr
Intel Server Board S2600bpb
Intel Server Board S2600bpbr
Intel Server Board S2600bpq
Intel Server Board S2600bpqr
Intel Server Board S2600bps
Intel Server Board S2600bpsr
Intel Server Board S2600stb
Intel Server Board S2600stbr
Intel Server Board S2600stq
Intel Server Board S2600stqr
Intel Server Board S2600wf0
Intel Server Board S2600wf0r
Intel Server Board S2600wfq
Intel Server Board S2600wfqr
Intel Server Board S2600wft
Intel Server Board S2600wftr
Intel Server System R1208wfqysr
Intel Server System R1208wftys
Intel Server System R1208wftysr
Intel Server System R1304wf0ys
Intel Server System R1304wf0ysr
Intel Server System R1304wftys
Intel Server System R1304wftysr
Intel Server System R2208wf0zs
Intel Server System R2208wf0zsr
Intel Server System R2208wfqzs
Intel Server System R2208wfqzsr
Intel Server System R2208wftzs
Intel Server System R2208wftzsr
Intel Server System R2224wfqzs
Intel Server System R2224wftzs
Intel Server System R2224wftzsr
Intel Server System R2308wftzs
Intel Server System R2308wftzsr
Intel Server System R2312wf0np
Intel Server System R2312wf0npr
Intel Server System R2312wfqzs
Intel Server System R2312wftzs
Intel Server System R2312wftzsr

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is CVE-2020-24474?

    CVE-2020-24474 is a buffer overflow vulnerability in the BMC firmware for some Intel Server Boards, Server Systems, and Compute Modules.

  • How severe is CVE-2020-24474?

    CVE-2020-24474 has a high severity rating with a score of 8 out of 10.

  • How can an authenticated user exploit CVE-2020-24474?

    An authenticated user may be able to enable escalation of privilege through adjacent access.

  • Which software versions are affected by CVE-2020-24474?

    Versions of the BMC firmware before 2.48.ce3e3bd2 are affected.

  • Where can I find more information about CVE-2020-24474?

    You can find more information about CVE-2020-24474 at the following link: [https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00476.html](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00476.html)

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203