CVE-2020-24475: Medium severity intel baseboard management controller firmware vulnerability

Published Jun 9, 2021
·
Updated

Improper initialization in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.48.ce3e3bd2 may allow an authenticated user to potentially enable denial of service via local access.

Affected Software

46 affected components
Intel Baseboard Management Controller firmware<2.48.ce3e3bd2
Intel Compute Module Hns2600bpb24r
Intel Compute Module Hns2600bpbr
Intel Compute Module Hns2600bpq24r
Intel Compute Module Hns2600bpqr
Intel Compute Module Hns2600bps24r
Intel Compute Module Hns2600bpsr
Intel Server Board S2600bpb
Intel Server Board S2600bpbr
Intel Server Board S2600bpq
Intel Server Board S2600bpqr
Intel Server Board S2600bps
Intel Server Board S2600bpsr
Intel Server Board S2600stb
Intel Server Board S2600stbr
Intel Server Board S2600stq
Intel Server Board S2600stqr
Intel Server Board S2600wf0
Intel Server Board S2600wf0r
Intel Server Board S2600wfq
Intel Server Board S2600wfqr
Intel Server Board S2600wft
Intel Server Board S2600wftr
Intel Server System R1208wfqysr
Intel Server System R1208wftys
Intel Server System R1208wftysr
Intel Server System R1304wf0ys
Intel Server System R1304wf0ysr
Intel Server System R1304wftys
Intel Server System R1304wftysr
Intel Server System R2208wf0zs
Intel Server System R2208wf0zsr
Intel Server System R2208wfqzs
Intel Server System R2208wfqzsr
Intel Server System R2208wftzs
Intel Server System R2208wftzsr
Intel Server System R2224wfqzs
Intel Server System R2224wftzs
Intel Server System R2224wftzsr
Intel Server System R2308wftzs
Intel Server System R2308wftzsr
Intel Server System R2312wf0np
Intel Server System R2312wf0npr
Intel Server System R2312wfqzs
Intel Server System R2312wftzs
Intel Server System R2312wftzsr

Event History

Jun 9, 2021
CVE Published
via MITRE·07:01 PM
Data Sourced
via MITRE·07:01 PM
DescriptionWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2020-24475?

CVE-2020-24475 refers to an improper initialization vulnerability in the BMC firmware for certain Intel Server Boards, Server Systems, and Compute Modules.

2

What is the severity of CVE-2020-24475?

The severity of CVE-2020-24475 is medium with a CVSS score of 5.5.

3

How does CVE-2020-24475 affect Intel Server Boards, Server Systems, and Compute Modules?

CVE-2020-24475 may allow an authenticated user to potentially enable denial of service via local access.

4

How can I fix CVE-2020-24475?

To fix CVE-2020-24475, update the BMC firmware to version 2.48.ce3e3bd2 or later.

5

Where can I find more information about CVE-2020-24475?

You can find more information about CVE-2020-24475 on the Intel Security Center Advisory page: [link](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00476.html)

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203