First published: Thu Feb 16 2023(Updated: )
Improper input validation in firmware for OpenBMC in some Intel(R) platforms before versions egs-0.91-179 and bhs-04-45 may allow an authenticated user to potentially enable denial of service via network access.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel Openbmc | <wht-1.01-61_0.72 | |
Intel C621a | ||
Intel C627a | ||
Intel C629a | ||
Intel Xeon Gold 5315y | ||
Intel Xeon Gold 5317 | ||
Intel Xeon Gold 5318h | ||
Intel Xeon Gold 5318n | ||
Intel Xeon Gold 5318s | ||
Intel Xeon Gold 5318y | ||
Intel Xeon Gold 5320 | ||
Intel Xeon Gold 5320h | ||
Intel Xeon Gold 5320t | ||
Intel Xeon Gold 6312u | ||
Intel Xeon Gold 6314u | ||
Intel Xeon Gold 6326 | ||
Intel Xeon Gold 6328h | ||
Intel Xeon Gold 6328hl | ||
Intel Xeon Gold 6330 | ||
Intel Xeon Gold 6330h | ||
Intel Xeon Gold 6330n | ||
Intel Xeon Gold 6334 | ||
Intel Xeon Gold 6336y | ||
Intel Xeon Gold 6338 | ||
Intel Xeon Gold 6338n | ||
Intel Xeon Gold 6338t | ||
Intel Xeon Gold 6342 | ||
Intel Xeon Gold 6346 | ||
Intel Xeon Gold 6348 | ||
Intel Xeon Gold 6348h | ||
Intel Xeon Gold 6354 | ||
Intel Xeon Platinum 8351n | ||
Intel Xeon Platinum 8352m | ||
Intel Xeon Platinum 8352s | ||
Intel Xeon Platinum 8352v | ||
Intel Xeon Platinum 8352y | ||
Intel Xeon Platinum 8353h | ||
Intel Xeon Platinum 8354h | ||
Intel Xeon Platinum 8356h | ||
Intel Xeon Platinum 8358 | ||
Intel Xeon Platinum 8358p | ||
Intel Xeon Platinum 8360h | ||
Intel Xeon Platinum 8360hl | ||
Intel Xeon Platinum 8360y | ||
Intel Xeon Platinum 8362 | ||
Intel Xeon Platinum 8368 | ||
Intel Xeon Platinum 8368q | ||
Intel Xeon Platinum 8376h | ||
Intel Xeon Platinum 8376hl | ||
Intel Xeon Platinum 8380 | ||
Intel Xeon Platinum 8380h | ||
Intel Xeon Platinum 8380hl | ||
Intel Xeon Silver 4309y | ||
Intel Xeon Silver 4310 | ||
Intel Xeon Silver 4310t | ||
Intel Xeon Silver 4314 | ||
Intel Xeon Silver 4316 | ||
Intel Openbmc | <egs-0.91-179 | |
Intel C741 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-29494.
The severity of CVE-2022-29494 is medium, with a CVSS score of 6.5.
Some Intel(R) platforms running OpenBMC firmware versions egs-0.9... up to exclusive egs-0.91-179 and bhs-04-45 are affected.
An authenticated user can potentially enable denial of service via network access.
You can find more information about CVE-2022-29494 in the Intel Security Advisory Intel-SA-00737.