Vulnerability Description
Buffer overflow in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.48.ce3e3bd2 may allow an authenticated user to potentially enable escalation of privilege via adjacent access.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Intel | Baseboard Management Controller Firmware | < 2.48.ce3e3bd2 |
| Intel | Compute Module Hns2600Bpb24R | - |
| Intel | Compute Module Hns2600Bpbr | - |
| Intel | Compute Module Hns2600Bpq24R | - |
| Intel | Compute Module Hns2600Bpqr | - |
| Intel | Compute Module Hns2600Bps24R | - |
| Intel | Compute Module Hns2600Bpsr | - |
| Intel | Server Board S2600Bpb | - |
| Intel | Server Board S2600Bpbr | - |
| Intel | Server Board S2600Bpq | - |
| Intel | Server Board S2600Bpqr | - |
| Intel | Server Board S2600Bps | - |
| Intel | Server Board S2600Bpsr | - |
| Intel | Server Board S2600Stb | - |
| Intel | Server Board S2600Stbr | - |
| Intel | Server Board S2600Stq | - |
| Intel | Server Board S2600Stqr | - |
| Intel | Server Board S2600Wf0 | - |
| Intel | Server Board S2600Wf0R | - |
| Intel | Server Board S2600Wfq | - |
Related Weaknesses (CWE)
References
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00476.Vendor Advisory
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00476.Vendor Advisory
FAQ
What is CVE-2020-24474?
CVE-2020-24474 is a vulnerability with a CVSS score of 8.0 (HIGH). Buffer overflow in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.48.ce3e3bd2 may allow an authenticated user to potentially enable escalation of...
How severe is CVE-2020-24474?
CVE-2020-24474 has been rated HIGH with a CVSS base score of 8.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-24474?
Check the references section above for vendor advisories and patch information. Affected products include: Intel Baseboard Management Controller Firmware, Intel Compute Module Hns2600Bpb24R, Intel Compute Module Hns2600Bpbr, Intel Compute Module Hns2600Bpq24R, Intel Compute Module Hns2600Bpqr.