CVE-2023-34431: Input Validation
Published Nov 14, 2023
ยทUpdated
Improper input validation in some Intel(R) Server Board BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access
Affected Software
66 affected components
All of the following
Intel Server Board M70klp2sb Firmware<01.04.0022
Intel Server Board M70klp2sb
All of the following
Intel Server System M70klp4s2uhh
Intel Server System M70klp4s2uhh Firmware<01.04.0022
All of the following
Intel Server Board M20ntp2sb
Intel Server Board M20ntp2sb Firmware<0022.d02
All of the following
Intel Server System M20ntp1ur304
Intel Server System M20ntp1ur304 Firmware<0022.d02
All of the following
Intel Server Board M10JNP2SB
Intel Server Board M10jnp2sb Firmware<7.219
All of the following
Intel Server Board S2600bpbr
Intel Server Board S2600bpbr Firmware<02.01.0015
All of the following
Intel Server Board S2600bps
Intel Server Board S2600bps Firmware<02.01.0015
All of the following
Intel Server Board S2600bpsr
Intel Server Board S2600bpsr Firmware<02.01.0015
All of the following
Intel Server Board S2600bpqr
Intel Server Board S2600bpqr Firmware<02.01.0015
All of the following
Intel Server Board S2600bpb
Intel Server Board S2600bpb Firmware<02.01.0015
All of the following
Intel Server Board S2600bpq
Intel Server Board S2600bpq Firmware<02.01.0015
All of the following
Intel Compute Module Hns2600bpblcr
Intel Compute Module Hns2600bpblcr Firmware<02.01.0015
All of the following
Intel Compute Module Hns2600bpblc
Intel Compute Module Hns2600bpblc Firmware<02.01.0015
All of the following
Intel Compute Module Hns2600bpblc24r Firmware<02.01.0015
Intel Compute Module Hns2600bpblc24r
All of the following
Intel Compute Module Hns2600bps Firmware<02.01.0015
Intel Compute Module Hns2600bps
All of the following
Intel Compute Module Hns2600bps24 Firmware<02.01.0015
Intel Compute Module Hns2600bps24
All of the following
Intel Compute Module Hns2600bpbr Firmware<02.01.0015
Intel Compute Module Hns2600bpbr
All of the following
Intel Compute Module Hns2600bpqr Firmware<02.01.0015
Intel Compute Module Hns2600bpqr
All of the following
Intel Compute Module Hns2600bpsr Firmware<02.01.0015
Intel Compute Module Hns2600bpsr
All of the following
Intel Compute Module Hns2600bps24r Firmware<02.01.0015
Intel Compute Module Hns2600bps24r
All of the following
Intel Compute Module Hns2600bpq24r Firmware<02.01.0015
Intel Compute Module Hns2600bpq24r
All of the following
Intel Compute Module Hns2600bpb24 Firmware<02.01.0015
Intel Compute Module Hns2600bpb24
All of the following
Intel Compute Module Hns2600bpb Firmware<02.01.0015
Intel Compute Module Hns2600bpb
All of the following
Intel Compute Module Hns2600bpblc24 Firmware<02.01.0015
Intel Compute Module Hns2600bpblc24
All of the following
Intel Compute Module Hns2600bpq Firmware<02.01.0015
Intel Compute Module Hns2600bpq
All of the following
Intel Compute Module Hns2600bpq24 Firmware<02.01.0015
Intel Compute Module Hns2600bpq24
All of the following
Intel Compute Module Liquid-cooled Hns2600bpbrct Firmware<02.01.0015
Intel Compute Module Liquid-cooled Hns2600bpbrct
All of the following
Intel Server System Vrn2224bpaf6 Firmware<02.01.0015
Intel Server System Vrn2224bpaf6
All of the following
Intel Server System Vrn2224bphy6 Firmware<02.01.0015
Intel Server System Vrn2224bphy6
All of the following
Intel Server System Mcb2208wfaf5 Firmware<02.01.0015
Intel Server System Mcb2208wfaf5
All of the following
Intel Server System Zsb2224bpaf2 Firmware<02.01.0015
Intel Server System Zsb2224bpaf2
All of the following
Intel Server System Zsb2224bphy1 Firmware<02.01.0015
Intel Server System Zsb2224bphy1
All of the following
Intel Server System Zsb2224bpaf1 Firmware<02.01.0015
Intel Server System Zsb2224bpaf1
Remediation
Event History
Nov 14, 2023
CVE Published
07:05 PM
Data Sourced
07:05 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-34431?
CVE-2023-34431 has a medium severity rating as it could allow a privileged user to escalate privileges via local access.
2
How do I fix CVE-2023-34431?
To fix CVE-2023-34431, it is recommended to update the affected Intel Server Board BIOS firmware to the latest version available.
3
Which Intel products are affected by CVE-2023-34431?
CVE-2023-34431 affects several Intel Server Boards and Systems, specifically those with BIOS firmware versions prior to 01.04.0022 for certain models.
4
What type of vulnerability is CVE-2023-34431?
CVE-2023-34431 is classified as an improper input validation vulnerability.
5
Can CVE-2023-34431 be exploited remotely?
No, CVE-2023-34431 cannot be exploited remotely; it requires local access to the affected system.