CVE-2023-49144: High severity openbmc vulnerability
Published Aug 14, 2024
·Updated
Out of bounds read in OpenBMC Firmware for some Intel(R) Server Platforms before versions egs-1.15-0, bhs-0.27 may allow a privileged user to potentially enable information disclosure via local access.
Affected Software
1 affected component
OpenBMC Firmware<egs-1.15-0, <bhs-0.27
Event History
Aug 14, 2024
CVE Published
via MITRE·01:45 PM
Data Sourced
via MITRE·01:45 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-49144?
CVE-2023-49144 has a severity rating that indicates a significant potential for information disclosure for privileged users.
2
How do I fix CVE-2023-49144?
To remediate CVE-2023-49144, upgrade to OpenBMC Firmware versions egs-1.15-0 or bhs-0.27 or later.
3
What type of vulnerability is CVE-2023-49144?
CVE-2023-49144 is classified as an out of bounds read vulnerability.
4
Who is affected by CVE-2023-49144?
CVE-2023-49144 affects certain Intel Server Platforms using specific versions of OpenBMC Firmware.
5
Can CVE-2023-49144 be exploited remotely?
No, CVE-2023-49144 requires local access for exploitation.