6.5

CVE-2022-29494

Improper input validation in firmware for OpenBMC in some Intel(R) platforms before versions egs-0.91-179 and bhs-04-45 may allow an authenticated user to potentially enable denial of service via network access.

Data is provided by the National Vulnerability Database (NVD)
IntelOpenbmc Version < wht-1.01-61_0.72
   IntelC621a Version-
   IntelC627a Version-
   IntelC629a Version-
   IntelXeon Gold 5315y Version-
   IntelXeon Gold 5317 Version-
   IntelXeon Gold 5318h Version-
   IntelXeon Gold 5318n Version-
   IntelXeon Gold 5318s Version-
   IntelXeon Gold 5318y Version-
   IntelXeon Gold 5320 Version-
   IntelXeon Gold 5320h Version-
   IntelXeon Gold 5320t Version-
   IntelXeon Gold 6312u Version-
   IntelXeon Gold 6314u Version-
   IntelXeon Gold 6326 Version-
   IntelXeon Gold 6328h Version-
   IntelXeon Gold 6328hl Version-
   IntelXeon Gold 6330 Version-
   IntelXeon Gold 6330h Version-
   IntelXeon Gold 6330n Version-
   IntelXeon Gold 6334 Version-
   IntelXeon Gold 6336y Version-
   IntelXeon Gold 6338 Version-
   IntelXeon Gold 6338n Version-
   IntelXeon Gold 6338t Version-
   IntelXeon Gold 6342 Version-
   IntelXeon Gold 6346 Version-
   IntelXeon Gold 6348 Version-
   IntelXeon Gold 6348h Version-
   IntelXeon Gold 6354 Version-
   IntelXeon Platinum 8351n Version-
   IntelXeon Platinum 8352m Version-
   IntelXeon Platinum 8352s Version-
   IntelXeon Platinum 8352v Version-
   IntelXeon Platinum 8352y Version-
   IntelXeon Platinum 8353h Version-
   IntelXeon Platinum 8354h Version-
   IntelXeon Platinum 8356h Version-
   IntelXeon Platinum 8358 Version-
   IntelXeon Platinum 8358p Version-
   IntelXeon Platinum 8360h Version-
   IntelXeon Platinum 8360hl Version-
   IntelXeon Platinum 8360y Version-
   IntelXeon Platinum 8362 Version-
   IntelXeon Platinum 8368 Version-
   IntelXeon Platinum 8368q Version-
   IntelXeon Platinum 8376h Version-
   IntelXeon Platinum 8376hl Version-
   IntelXeon Platinum 8380 Version-
   IntelXeon Platinum 8380h Version-
   IntelXeon Platinum 8380hl Version-
   IntelXeon Silver 4309y Version-
   IntelXeon Silver 4310 Version-
   IntelXeon Silver 4310t Version-
   IntelXeon Silver 4314 Version-
   IntelXeon Silver 4316 Version-
IntelOpenbmc Version < egs-0.91-179
   IntelC741 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.12% 0.279
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
secure@intel.com 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.