First published: Thu Feb 16 2023(Updated: )
Improper input validation in firmware for OpenBMC in some Intel(R) platforms before versions egs-0.91-179 and bhs-04-45 may allow an authenticated user to potentially enable denial of service via network access.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel OpenBMC Firmware | <wht-1.01-61_0.72 | |
Intel C621A Firmware | ||
Intel C627A Firmware | ||
Intel C629A Firmware | ||
Intel Xeon Gold 5315y Firmware | ||
Intel Xeon Gold 5317 Firmware | ||
Intel Xeon Gold 5318h Firmware | ||
Intel Xeon Gold 5318n Firmware | ||
Intel Xeon Gold 5318s Firmware | ||
Intel Xeon Gold 5318y Firmware | ||
Intel Xeon Gold 5320 Firmware | ||
Intel Xeon Gold 5320h Firmware | ||
Intel Xeon Gold 5320t Firmware | ||
Intel Xeon Gold 6312U Firmware | ||
Intel Xeon Gold 6314u Firmware | ||
Intel Xeon Gold 6326 Firmware | ||
Intel Xeon Gold 6328H Firmware | ||
Intel Xeon Gold 6328HL | ||
Intel Xeon Gold 6330 Firmware | ||
Intel Xeon Gold 6330H Firmware | ||
Intel Xeon Gold 6330n Firmware | ||
Intel Xeon Gold 6334 Firmware | ||
Intel Xeon Gold 6336Y | ||
Intel Xeon Gold 6338 | ||
Intel Xeon Gold 6338n Firmware | ||
Intel Xeon Gold 6338T | ||
Intel Xeon Gold 6342 Firmware | ||
Intel Xeon Gold 6346 Firmware | ||
Intel Xeon Gold 6348 Firmware | ||
Intel Xeon Gold 6348H | ||
Intel Xeon Gold 6354 Firmware | ||
Intel Xeon Platinum 8351n | ||
Intel Xeon Platinum 8352M | ||
Intel Xeon Platinum 8352S | ||
Intel Xeon Platinum 8352v | ||
Intel Xeon Platinum 8352y Firmware | ||
Intel Xeon Platinum 8353h Firmware | ||
Intel Xeon Platinum 8354H | ||
Intel Xeon Platinum 8356h Firmware | ||
Intel Xeon Platinum 8358 | ||
Intel Xeon Platinum Processors | ||
Intel Xeon Platinum 8360h Firmware | ||
Intel Xeon Platinum 8360HL | ||
Intel Xeon Platinum 8360Y | ||
Intel Xeon Platinum Processors | ||
Intel Xeon Platinum 8368 | ||
Intel Xeon Platinum 8368q Firmware | ||
Intel Xeon Platinum 8376H Firmware | ||
Intel Xeon Platinum 8376hl Firmware | ||
Intel Xeon Platinum 8380 | ||
Intel Xeon Platinum 8380H Firmware | ||
Intel Xeon Platinum 8380hl | ||
Intel Xeon Silver 4309Y | ||
Intel Xeon Silver 4310 | ||
Intel Xeon Silver 4310t Firmware | ||
Intel Xeon Silver 4314 Firmware | ||
Intel Xeon Silver 4316 | ||
Intel OpenBMC Firmware | <egs-0.91-179 | |
Intel C741 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-29494.
The severity of CVE-2022-29494 is medium, with a CVSS score of 6.5.
Some Intel(R) platforms running OpenBMC firmware versions egs-0.9... up to exclusive egs-0.91-179 and bhs-04-45 are affected.
An authenticated user can potentially enable denial of service via network access.
You can find more information about CVE-2022-29494 in the Intel Security Advisory Intel-SA-00737.