7.2

CVE-2020-26122

Inspur NF5266M5 through 3.21.2 and other server M5 devices allow remote code execution via administrator privileges. The Baseboard Management Controller (BMC) program of INSPUR server is weak in checking the firmware and lacks the signature verification mechanism, the attacker who obtains the administrator's rights can control the BMC by inserting malicious code into the firmware program and bypassing the current verification mechanism to upgrade the BMC.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
InspurNf8480m5 Firmware Version < 1.19.34
   InspurNf8480m5 Version-
InspurNf8260m5 Firmware Version < 1.19.34
   InspurNf8260m5 Version-
InspurNs5162m5 Firmware Version < 4.5.3
   InspurNs5162m5 Version-
InspurNs5488m5 Firmware Version < 1.19.33
   InspurNs5488m5 Version-
InspurNs5484m5 Firmware Version < 1.19.33
   InspurNs5484m5 Version-
InspurNs5482m5 Firmware Version < 1.19.33
   InspurNs5482m5 Version-
InspurNf5280m5 Firmware Version < 4.26.6
   InspurNf5280m5 Version-
InspurNf5468m5 Firmware Version < 1.18.51
   InspurNf5468m5 Version-
InspurNf5488m5-d Firmware Version < 1.18.51
   InspurNf5488m5-d Version-
InspurNf5180m5 Firmware Version < 4.18.2
   InspurNf5180m5 Version-
InspurNf5270m5 Firmware Version < 4.9.1
   InspurNf5270m5 Version-
InspurNf5260m5 Firmware Version < 3.8.0
   InspurNf5260m5 Version-
InspurNf5266m5 Firmware Version < 3.21.3
   InspurNf5266m5 Version-
InspurNf5466m5 Firmware Version < 4.28.0
   InspurNf5466m5 Version-
InspurNf5486m5 Firmware Version < 3.22.0
   InspurNf5486m5 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.64% 0.697
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
CWE-347 Improper Verification of Cryptographic Signature

The product does not verify, or incorrectly verifies, the cryptographic signature for data.