CVE-2020-5633: Critical severity NEC Baseboard Management Controller vulnerability
Multiple NEC products (Express5800/T110j, Express5800/T110j-S, Express5800/T110j (2nd-Gen), Express5800/T110j-S (2nd-Gen), iStorage NS100Ti, and Express5800/GT110j) where Baseboard Management Controller (BMC) firmware Rev1.09 and earlier is applied allows remote attackers to bypass authentication and then obtain/modify BMC setting information, obtain monitoring information, or reboot/shut down the vulnerable product via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this NEC product vulnerability?
The vulnerability ID for this NEC product vulnerability is CVE-2020-5633.
Which NEC products are affected by this vulnerability?
Multiple NEC products are affected by this vulnerability, including Express5800/T110j, Express5800/T110j-S, Express5800/T110j (2nd-Gen), Express5800/T110j-S (2nd-Gen), iStorage NS100Ti, and Express5800/GT110j.
What is the severity of CVE-2020-5633?
The severity of CVE-2020-5633 is critical with a CVSS score of 9.8.
How can remote attackers exploit this vulnerability?
Remote attackers can exploit this vulnerability to bypass authentication and gain unauthorized access to affected devices.
Is there a fix available for this vulnerability?
Yes, a fix is available for this vulnerability. It is recommended to update the BMC firmware to version 1.10 or later.