CVE-2020-26122: High severity inspur nf8480m5 firmware vulnerability
Inspur NF5266M5 through 3.21.2 and other server M5 devices allow remote code execution via administrator privileges. The Baseboard Management Controller (BMC) program of INSPUR server is weak in checking the firmware and lacks the signature verification mechanism, the attacker who obtains the administrator's rights can control the BMC by inserting malicious code into the firmware program and bypassing the current verification mechanism to upgrade the BMC.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-26122?
CVE-2020-26122 is classified with a severity that potentially allows remote code execution due to inadequate firmware verification.
How do I fix CVE-2020-26122?
To mitigate CVE-2020-26122, update the firmware of your Inspur NF5266M5 or other affected server M5 devices to the latest version.
What causes CVE-2020-26122?
CVE-2020-26122 is caused by the Baseboard Management Controller (BMC) failing to properly verify firmware signatures.
Which devices are affected by CVE-2020-26122?
CVE-2020-26122 affects several Inspur M5 server models, including NF5266M5, NF5260M5, and others with specific firmware versions.
Can CVE-2020-26122 be exploited remotely?
Yes, CVE-2020-26122 can be exploited remotely as it allows an attacker with administrator privileges to execute arbitrary code.