CVE-2020-26122: High severity inspur nf8480m5 firmware vulnerability

Published Dec 7, 2020
·
Updated

Inspur NF5266M5 through 3.21.2 and other server M5 devices allow remote code execution via administrator privileges. The Baseboard Management Controller (BMC) program of INSPUR server is weak in checking the firmware and lacks the signature verification mechanism, the attacker who obtains the administrator's rights can control the BMC by inserting malicious code into the firmware program and bypassing the current verification mechanism to upgrade the BMC.

Affected Software

30 affected components
Inspur Nf8480m5 Firmware<1.19.34
Inspur Nf8480m5
Inspur Nf8260m5 Firmware<1.19.34
Inspur Nf8260m5
Inspur Ns5162m5 Firmware<4.5.3
Inspur Ns5162m5
Inspur Ns5488m5 Firmware<1.19.33
Inspur Ns5488m5
Inspur Ns5484m5 Firmware<1.19.33
Inspur Ns5484m5
Inspur Ns5482m5 Firmware<1.19.33
Inspur Ns5482m5
Inspur Nf5280m5 Firmware<4.26.6
Inspur Nf5280m5
Inspur Nf5468m5 Firmware<1.18.51
Inspur Nf5468m5
Inspur Nf5488m5-d Firmware<1.18.51
Inspur Nf5488m5-d
Inspur Nf5180m5 Firmware<4.18.2
Inspur Nf5180m5
Inspur Nf5270m5 Firmware<4.9.1
Inspur Nf5270m5
Inspur Nf5260m5 Firmware<3.8.0
Inspur Nf5260m5
Inspur Nf5266m5 Firmware<3.21.3
Inspur NF5266M5
Inspur Nf5466m5 Firmware<4.28.0
Inspur Nf5466m5
Inspur Nf5486m5 Firmware<3.22.0
Inspur Nf5486m5

Event History

Dec 7, 2020
CVE Published
via MITRE·03:34 PM
Data Sourced
via MITRE·03:34 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2020-26122?

CVE-2020-26122 is classified with a severity that potentially allows remote code execution due to inadequate firmware verification.

2

How do I fix CVE-2020-26122?

To mitigate CVE-2020-26122, update the firmware of your Inspur NF5266M5 or other affected server M5 devices to the latest version.

3

What causes CVE-2020-26122?

CVE-2020-26122 is caused by the Baseboard Management Controller (BMC) failing to properly verify firmware signatures.

4

Which devices are affected by CVE-2020-26122?

CVE-2020-26122 affects several Inspur M5 server models, including NF5266M5, NF5260M5, and others with specific firmware versions.

5

Can CVE-2020-26122 be exploited remotely?

Yes, CVE-2020-26122 can be exploited remotely as it allows an attacker with administrator privileges to execute arbitrary code.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203