First published: Thu Feb 16 2023(Updated: )
Out of bounds read in firmware for OpenBMC in some Intel(R) platforms before version 0.72 may allow unauthenticated user to potentially enable denial of service via network access.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
openbmc-project OpenBMC | <0.72 | |
Intel c621a | ||
Intel c624a | ||
Intel c627a | ||
Intel c629a | ||
Intel Xeon Gold 5315y Firmware | ||
Intel Xeon Gold 5317 | ||
Intel Xeon Gold 5318h Firmware | ||
Intel Xeon Gold 5318N | ||
Intel Xeon Gold 5318s | ||
Intel Xeon Gold 5318y Firmware | ||
Intel Xeon Gold 5320 Firmware | ||
Intel Xeon Gold 5320h Firmware | ||
Intel Xeon Gold 5320t Firmware | ||
Intel Xeon Gold 6312u Firmware | ||
Intel Xeon Gold 6314u | ||
Intel Xeon Gold 6326 Firmware | ||
Intel Xeon Gold 6328H | ||
Intel Xeon Gold 6328HL | ||
Intel Xeon Gold 6330 Firmware | ||
Intel Xeon Gold 6330h Firmware | ||
Intel Xeon Gold 6330N | ||
Intel Xeon Gold 6334 Firmware | ||
Intel Xeon Gold 6336Y | ||
Intel Xeon Gold 6338 | ||
Intel Xeon Gold 6338n Firmware | ||
Intel Xeon Gold 6338t | ||
Intel Xeon Gold 6342 Firmware | ||
Intel Xeon Gold 6346 Firmware | ||
Intel Xeon Gold 6348 Firmware | ||
Intel Xeon Gold 6348H | ||
Intel Xeon Gold 6354 Firmware | ||
Intel Xeon Platinum 8351n | ||
Intel Xeon Platinum 8352M | ||
Intel Xeon Platinum 8352s | ||
Intel Xeon Platinum 8352v | ||
Intel Xeon Platinum 8352y Firmware | ||
Intel Xeon Platinum 8353h Firmware | ||
Intel Xeon Platinum 8354h | ||
Intel Xeon Platinum 8356h | ||
Intel Xeon Platinum 8358 | ||
Intel Xeon Platinum Processors | ||
Intel Xeon Platinum 8360h Firmware | ||
Intel Xeon Platinum 8360HL | ||
Intel Xeon Platinum 8360Y | ||
Intel Xeon Platinum Processors | ||
Intel Xeon Platinum 8368 | ||
Intel Xeon Platinum 8368Q | ||
Intel Xeon Platinum 8376H | ||
Intel Xeon Platinum 8376hl Firmware | ||
Intel Xeon Platinum 8380 | ||
Intel Xeon Platinum 8380H Firmware | ||
Intel Xeon Platinum 8380hl | ||
Intel Xeon Silver 4309Y | ||
Intel Xeon Silver 4310 | ||
Intel Xeon Silver 4310t Firmware | ||
Intel Xeon Silver 4314 Firmware | ||
Intel Xeon Silver 4316 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-35729 is an out of bounds read vulnerability in the firmware for OpenBMC in some Intel platforms.
CVE-2022-35729 may allow an unauthenticated user to potentially enable denial of service via network access.
Intel platforms with OpenBMC firmware versions before 0.72 may be affected.
CVE-2022-35729 has a severity rating of 7.5 (high).
You can find more information about CVE-2022-35729 on the Intel Security Center Advisory page: http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00737.html