8.2

CVE-2023-34431

Improper input validation in some Intel(R) Server Board BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IntelServer Board M70klp2sb Firmware Version < 01.04.0022
   IntelServer Board M70klp2sb Version-
IntelServer System M70klp4s2uhh Firmware Version < 01.04.0022
   IntelServer System M70klp4s2uhh Version-
IntelServer Board M20ntp2sb Firmware Version < 0022.d02
   IntelServer Board M20ntp2sb Version-
IntelServer Board M10jnp2sb Firmware Version < 7.219
   IntelServer Board M10jnp2sb Version-
IntelServer Board S2600bpbr Firmware Version < 02.01.0015
   IntelServer Board S2600bpbr Version-
IntelServer Board S2600bps Firmware Version < 02.01.0015
   IntelServer Board S2600bps Version-
IntelServer Board S2600bpsr Firmware Version < 02.01.0015
   IntelServer Board S2600bpsr Version-
IntelServer Board S2600bpqr Firmware Version < 02.01.0015
   IntelServer Board S2600bpqr Version-
IntelServer Board S2600bpb Firmware Version < 02.01.0015
   IntelServer Board S2600bpb Version-
IntelServer Board S2600bpq Firmware Version < 02.01.0015
   IntelServer Board S2600bpq Version-
IntelCompute Module Hns2600bps Firmware Version < 02.01.0015
   IntelCompute Module Hns2600bps Version-
IntelCompute Module Hns2600bpbr Firmware Version < 02.01.0015
   IntelCompute Module Hns2600bpbr Version-
IntelCompute Module Hns2600bpqr Firmware Version < 02.01.0015
   IntelCompute Module Hns2600bpqr Version-
IntelCompute Module Hns2600bpsr Firmware Version < 02.01.0015
   IntelCompute Module Hns2600bpsr Version-
IntelCompute Module Hns2600bpb Firmware Version < 02.01.0015
   IntelCompute Module Hns2600bpb Version-
IntelCompute Module Hns2600bpq Firmware Version < 02.01.0015
   IntelCompute Module Hns2600bpq Version-
IntelServer System Vrn2224bpaf6 Firmware Version < 02.01.0015
   IntelServer System Vrn2224bpaf6 Version-
IntelServer System Vrn2224bphy6 Firmware Version < 02.01.0015
   IntelServer System Vrn2224bphy6 Version-
IntelServer System Mcb2208wfaf5 Firmware Version < 02.01.0015
   IntelServer System Mcb2208wfaf5 Version-
IntelServer System Zsb2224bpaf2 Firmware Version < 02.01.0015
   IntelServer System Zsb2224bpaf2 Version-
IntelServer System Zsb2224bphy1 Firmware Version < 02.01.0015
   IntelServer System Zsb2224bphy1 Version-
IntelServer System Zsb2224bpaf1 Firmware Version < 02.01.0015
   IntelServer System Zsb2224bpaf1 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.06% 0.177
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
secure@intel.com 8.2 1.5 6
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.