CVE-2023-34431: Input Validation

Published Nov 14, 2023
ยท
Updated

Improper input validation in some Intel(R) Server Board BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access

Affected Software

66 affected components
All of the following
Intel Server Board M70klp2sb Firmware<01.04.0022
Intel Server Board M70klp2sb
All of the following
Intel Server System M70klp4s2uhh
Intel Server System M70klp4s2uhh Firmware<01.04.0022
All of the following
Intel Server Board M20ntp2sb
Intel Server Board M20ntp2sb Firmware<0022.d02
All of the following
Intel Server System M20ntp1ur304
Intel Server System M20ntp1ur304 Firmware<0022.d02
All of the following
Intel Server Board M10JNP2SB
Intel Server Board M10jnp2sb Firmware<7.219
All of the following
Intel Server Board S2600bpbr
Intel Server Board S2600bpbr Firmware<02.01.0015
All of the following
Intel Server Board S2600bps
Intel Server Board S2600bps Firmware<02.01.0015
All of the following
Intel Server Board S2600bpsr
Intel Server Board S2600bpsr Firmware<02.01.0015
All of the following
Intel Server Board S2600bpqr
Intel Server Board S2600bpqr Firmware<02.01.0015
All of the following
Intel Server Board S2600bpb
Intel Server Board S2600bpb Firmware<02.01.0015
All of the following
Intel Server Board S2600bpq
Intel Server Board S2600bpq Firmware<02.01.0015
All of the following
Intel Compute Module Hns2600bpblcr
Intel Compute Module Hns2600bpblcr Firmware<02.01.0015
All of the following
Intel Compute Module Hns2600bpblc
Intel Compute Module Hns2600bpblc Firmware<02.01.0015
All of the following
Intel Compute Module Hns2600bpblc24r Firmware<02.01.0015
Intel Compute Module Hns2600bpblc24r
All of the following
Intel Compute Module Hns2600bps Firmware<02.01.0015
Intel Compute Module Hns2600bps
All of the following
Intel Compute Module Hns2600bps24 Firmware<02.01.0015
Intel Compute Module Hns2600bps24
All of the following
Intel Compute Module Hns2600bpbr Firmware<02.01.0015
Intel Compute Module Hns2600bpbr
All of the following
Intel Compute Module Hns2600bpqr Firmware<02.01.0015
Intel Compute Module Hns2600bpqr
All of the following
Intel Compute Module Hns2600bpsr Firmware<02.01.0015
Intel Compute Module Hns2600bpsr
All of the following
Intel Compute Module Hns2600bps24r Firmware<02.01.0015
Intel Compute Module Hns2600bps24r
All of the following
Intel Compute Module Hns2600bpq24r Firmware<02.01.0015
Intel Compute Module Hns2600bpq24r
All of the following
Intel Compute Module Hns2600bpb24 Firmware<02.01.0015
Intel Compute Module Hns2600bpb24
All of the following
Intel Compute Module Hns2600bpb Firmware<02.01.0015
Intel Compute Module Hns2600bpb
All of the following
Intel Compute Module Hns2600bpblc24 Firmware<02.01.0015
Intel Compute Module Hns2600bpblc24
All of the following
Intel Compute Module Hns2600bpq Firmware<02.01.0015
Intel Compute Module Hns2600bpq
All of the following
Intel Compute Module Hns2600bpq24 Firmware<02.01.0015
Intel Compute Module Hns2600bpq24
All of the following
Intel Compute Module Liquid-cooled Hns2600bpbrct Firmware<02.01.0015
Intel Compute Module Liquid-cooled Hns2600bpbrct
All of the following
Intel Server System Vrn2224bpaf6 Firmware<02.01.0015
Intel Server System Vrn2224bpaf6
All of the following
Intel Server System Vrn2224bphy6 Firmware<02.01.0015
Intel Server System Vrn2224bphy6
All of the following
Intel Server System Mcb2208wfaf5 Firmware<02.01.0015
Intel Server System Mcb2208wfaf5
All of the following
Intel Server System Zsb2224bpaf2 Firmware<02.01.0015
Intel Server System Zsb2224bpaf2
All of the following
Intel Server System Zsb2224bphy1 Firmware<02.01.0015
Intel Server System Zsb2224bphy1
All of the following
Intel Server System Zsb2224bpaf1 Firmware<02.01.0015
Intel Server System Zsb2224bpaf1

Event History

Nov 14, 2023
CVE Published
07:05 PM
Data Sourced
07:05 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2023-34431?

CVE-2023-34431 has a medium severity rating as it could allow a privileged user to escalate privileges via local access.

2

How do I fix CVE-2023-34431?

To fix CVE-2023-34431, it is recommended to update the affected Intel Server Board BIOS firmware to the latest version available.

3

Which Intel products are affected by CVE-2023-34431?

CVE-2023-34431 affects several Intel Server Boards and Systems, specifically those with BIOS firmware versions prior to 01.04.0022 for certain models.

4

What type of vulnerability is CVE-2023-34431?

CVE-2023-34431 is classified as an improper input validation vulnerability.

5

Can CVE-2023-34431 be exploited remotely?

No, CVE-2023-34431 cannot be exploited remotely; it requires local access to the affected system.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
ยฉ 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203