8

CVE-2020-24474

Buffer overflow in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.48.ce3e3bd2 may allow an authenticated user to potentially enable escalation of privilege via adjacent access.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IntelBaseboard Management Controller Firmware Version < 2.48.ce3e3bd2
   IntelCompute Module Hns2600bpb24r Version-
   IntelCompute Module Hns2600bpbr Version-
   IntelCompute Module Hns2600bpq24r Version-
   IntelCompute Module Hns2600bpqr Version-
   IntelCompute Module Hns2600bps24r Version-
   IntelCompute Module Hns2600bpsr Version-
   IntelServer Board S2600bpb Version-
   IntelServer Board S2600bpbr Version-
   IntelServer Board S2600bpq Version-
   IntelServer Board S2600bpqr Version-
   IntelServer Board S2600bps Version-
   IntelServer Board S2600bpsr Version-
   IntelServer Board S2600stb Version-
   IntelServer Board S2600stbr Version-
   IntelServer Board S2600stq Version-
   IntelServer Board S2600stqr Version-
   IntelServer Board S2600wf0 Version-
   IntelServer Board S2600wf0r Version-
   IntelServer Board S2600wfq Version-
   IntelServer Board S2600wfqr Version-
   IntelServer Board S2600wft Version-
   IntelServer Board S2600wftr Version-
   IntelServer System R1208wfqysr Version-
   IntelServer System R1208wftys Version-
   IntelServer System R1208wftysr Version-
   IntelServer System R1304wf0ys Version-
   IntelServer System R1304wf0ysr Version-
   IntelServer System R1304wftys Version-
   IntelServer System R1304wftysr Version-
   IntelServer System R2208wf0zs Version-
   IntelServer System R2208wf0zsr Version-
   IntelServer System R2208wfqzs Version-
   IntelServer System R2208wfqzsr Version-
   IntelServer System R2208wftzs Version-
   IntelServer System R2208wftzsr Version-
   IntelServer System R2224wfqzs Version-
   IntelServer System R2224wftzs Version-
   IntelServer System R2224wftzsr Version-
   IntelServer System R2308wftzs Version-
   IntelServer System R2308wftzsr Version-
   IntelServer System R2312wf0np Version-
   IntelServer System R2312wf0npr Version-
   IntelServer System R2312wfqzs Version-
   IntelServer System R2312wftzs Version-
   IntelServer System R2312wftzsr Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.14% 0.304
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8 2.1 5.9
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 5.2 5.1 6.4
AV:A/AC:L/Au:S/C:P/I:P/A:P
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.