First published: Thu Feb 16 2023(Updated: )
Out of bounds read in firmware for OpenBMC in some Intel(R) platforms before version 0.72 may allow unauthenticated user to potentially enable denial of service via network access.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Openbmc-project Openbmc | <0.72 | |
Intel C621a | ||
Intel C624a | ||
Intel C627a | ||
Intel C629a | ||
Intel Xeon Gold 5315y | ||
Intel Xeon Gold 5317 | ||
Intel Xeon Gold 5318h | ||
Intel Xeon Gold 5318n | ||
Intel Xeon Gold 5318s | ||
Intel Xeon Gold 5318y | ||
Intel Xeon Gold 5320 | ||
Intel Xeon Gold 5320h | ||
Intel Xeon Gold 5320t | ||
Intel Xeon Gold 6312u | ||
Intel Xeon Gold 6314u | ||
Intel Xeon Gold 6326 | ||
Intel Xeon Gold 6328h | ||
Intel Xeon Gold 6328hl | ||
Intel Xeon Gold 6330 | ||
Intel Xeon Gold 6330h | ||
Intel Xeon Gold 6330n | ||
Intel Xeon Gold 6334 | ||
Intel Xeon Gold 6336y | ||
Intel Xeon Gold 6338 | ||
Intel Xeon Gold 6338n | ||
Intel Xeon Gold 6338t | ||
Intel Xeon Gold 6342 | ||
Intel Xeon Gold 6346 | ||
Intel Xeon Gold 6348 | ||
Intel Xeon Gold 6348h | ||
Intel Xeon Gold 6354 | ||
Intel Xeon Platinum 8351n | ||
Intel Xeon Platinum 8352m | ||
Intel Xeon Platinum 8352s | ||
Intel Xeon Platinum 8352v | ||
Intel Xeon Platinum 8352y | ||
Intel Xeon Platinum 8353h | ||
Intel Xeon Platinum 8354h | ||
Intel Xeon Platinum 8356h | ||
Intel Xeon Platinum 8358 | ||
Intel Xeon Platinum 8358p | ||
Intel Xeon Platinum 8360h | ||
Intel Xeon Platinum 8360hl | ||
Intel Xeon Platinum 8360y | ||
Intel Xeon Platinum 8362 | ||
Intel Xeon Platinum 8368 | ||
Intel Xeon Platinum 8368q | ||
Intel Xeon Platinum 8376h | ||
Intel Xeon Platinum 8376hl | ||
Intel Xeon Platinum 8380 | ||
Intel Xeon Platinum 8380h | ||
Intel Xeon Platinum 8380hl | ||
Intel Xeon Silver 4309y | ||
Intel Xeon Silver 4310 | ||
Intel Xeon Silver 4310t | ||
Intel Xeon Silver 4314 | ||
Intel Xeon Silver 4316 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-35729 is an out of bounds read vulnerability in the firmware for OpenBMC in some Intel platforms.
CVE-2022-35729 may allow an unauthenticated user to potentially enable denial of service via network access.
Intel platforms with OpenBMC firmware versions before 0.72 may be affected.
CVE-2022-35729 has a severity rating of 7.5 (high).
You can find more information about CVE-2022-35729 on the Intel Security Center Advisory page: http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00737.html