7.8

CVE-2019-11170

Authentication bypass in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable information disclosure, escalation of privilege and/or denial of service via local access.

Data is provided by the National Vulnerability Database (NVD)
IntelBaseboard Management Controller Firmware Version < 2.18
   IntelBbs2600bpb Version-
   IntelBbs2600bpbr Version-
   IntelBbs2600bpq Version-
   IntelBbs2600bpqr Version-
   IntelBbs2600bps Version-
   IntelBbs2600bpsr Version-
   IntelBbs2600stb Version-
   IntelBbs2600stbr Version-
   IntelBbs2600stq Version-
   IntelBbs2600stqr Version-
   IntelHns2600bpb Version-
   IntelHns2600bpb24 Version-
   IntelHns2600bpb24r Version-
   IntelHns2600bpb24rx Version-
   IntelHns2600bpblc Version-
   IntelHns2600bpblc24 Version-
   IntelHns2600bpblc24r Version-
   IntelHns2600bpblcr Version-
   IntelHns2600bpbr Version-
   IntelHns2600bpbrx Version-
   IntelHns2600bpq Version-
   IntelHns2600bpq24 Version-
   IntelHns2600bpq24r Version-
   IntelHns2600bpqr Version-
   IntelHns2600bps Version-
   IntelHns2600bps24 Version-
   IntelHns2600bps24r Version-
   IntelHns2600bpsr Version-
   IntelHpchns2600bpbr Version-
   IntelHpchns2600bpqr Version-
   IntelHpchns2600bpsr Version-
   IntelHpcr1208wfqysr Version-
   IntelHpcr1208wftysr Version-
   IntelHpcr1304wf0ysr Version-
   IntelHpcr1304wftysr Version-
   IntelHpcr2208wf0zsr Version-
   IntelHpcr2208wfqzsr Version-
   IntelHpcr2208wftzsr Version-
   IntelHpcr2208wftzsrx Version-
   IntelHpcr2224wftzsr Version-
   IntelHpcr2308wftzsr Version-
   IntelHpcr2312wf0npr Version-
   IntelHpcr2312wftzsr Version-
   IntelR1208wfqysr Version-
   IntelR1208wftys Version-
   IntelR1208wftysr Version-
   IntelR1304wf0ys Version-
   IntelR1304wf0ysr Version-
   IntelR1304wftys Version-
   IntelR1304wftysr Version-
   IntelR2208wf0zs Version-
   IntelR2208wf0zsr Version-
   IntelR2208wfqzs Version-
   IntelR2208wfqzsr Version-
   IntelR2208wftzs Version-
   IntelR2208wftzsr Version-
   IntelR2208wftzsrx Version-
   IntelR2224wfqzs Version-
   IntelR2224wftzs Version-
   IntelR2224wftzsr Version-
   IntelR2308wftzs Version-
   IntelR2308wftzsr Version-
   IntelR2312wf0np Version-
   IntelR2312wf0npr Version-
   IntelR2312wfqzs Version-
   IntelR2312wftzs Version-
   IntelR2312wftzsr Version-
   IntelS2600stb Version-
   IntelS2600stbr Version-
   IntelS2600stq Version-
   IntelS2600stqr Version-
   IntelS2600wf0 Version-
   IntelS2600wf0r Version-
   IntelS2600wfq Version-
   IntelS2600wfqr Version-
   IntelS2600wft Version-
   IntelS2600wftr Version-
   IntelS9232wk1hlc Version-
   IntelS9232wk2hac Version-
   IntelS9232wk2hlc Version-
   IntelS9248wk1hlc Version-
   IntelS9248wk2hac Version-
   IntelS9248wk2hlc Version-
   IntelS9256wk1hlc Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.04% 0.101
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.