First published: Wed Jun 09 2021(Updated: )
Buffer overflow in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.48.ce3e3bd2 may allow an authenticated user to potentially enable escalation of privilege via adjacent access.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
<2.48.ce3e3bd2 | ||
Intel Compute Module Hns2600bpb24r | ||
Intel Compute Module Hns2600bpbr | ||
Intel Compute Module Hns2600bpq24r | ||
Intel Compute Module Hns2600bpqr | ||
Intel Compute Module Hns2600bps24r | ||
Intel Compute Module Hns2600bpsr | ||
Intel Server Board S2600bpb | ||
Intel Server Board S2600bpbr | ||
Intel Server Board S2600bpq | ||
Intel Server Board S2600bpqr | ||
Intel Server Board S2600bps | ||
Intel Server Board S2600bpsr | ||
Intel Server Board S2600stb | ||
Intel Server Board S2600stbr | ||
Intel Server Board S2600stq | ||
Intel Server Board S2600stqr | ||
Intel Server Board S2600wf0 | ||
Intel Server Board S2600wf0r | ||
Intel Server Board S2600wfq | ||
Intel Server Board S2600wfqr | ||
Intel Server Board S2600wft | ||
Intel Server Board S2600wftr | ||
Intel Server System R1208wfqysr | ||
Intel Server System R1208wftys | ||
Intel Server System R1208wftysr | ||
Intel Server System R1304wf0ys | ||
Intel Server System R1304wf0ysr | ||
Intel Server System R1304wftys | ||
Intel Server System R1304wftysr | ||
Intel Server System R2208wf0zs | ||
Intel Server System R2208wf0zsr | ||
Intel Server System R2208wfqzs | ||
Intel Server System R2208wfqzsr | ||
Intel Server System R2208wftzs | ||
Intel Server System R2208wftzsr | ||
Intel Server System R2224wfqzs | ||
Intel Server System R2224wftzs | ||
Intel Server System R2224wftzsr | ||
Intel Server System R2308wftzs | ||
Intel Server System R2308wftzsr | ||
Intel Server System R2312wf0np | ||
Intel Server System R2312wf0npr | ||
Intel Server System R2312wfqzs | ||
Intel Server System R2312wftzs | ||
Intel Server System R2312wftzsr |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-24474 is a buffer overflow vulnerability in the BMC firmware for some Intel Server Boards, Server Systems, and Compute Modules.
CVE-2020-24474 has a high severity rating with a score of 8 out of 10.
An authenticated user may be able to enable escalation of privilege through adjacent access.
Versions of the BMC firmware before 2.48.ce3e3bd2 are affected.
You can find more information about CVE-2020-24474 at the following link: [https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00476.html](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00476.html)