Vulnerability Description
Improper input validation in firmware for OpenBMC in some Intel(R) platforms before versions egs-0.91-179 and bhs-04-45 may allow an authenticated user to potentially enable denial of service via network access.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Intel | Openbmc | < wht-1.01-61_0.72 |
| Intel | C621A | - |
| Intel | C627A | - |
| Intel | C629A | - |
| Intel | Xeon Gold 5315Y | - |
| Intel | Xeon Gold 5317 | - |
| Intel | Xeon Gold 5318H | - |
| Intel | Xeon Gold 5318N | - |
| Intel | Xeon Gold 5318S | - |
| Intel | Xeon Gold 5318Y | - |
| Intel | Xeon Gold 5320 | - |
| Intel | Xeon Gold 5320H | - |
| Intel | Xeon Gold 5320T | - |
| Intel | Xeon Gold 6312U | - |
| Intel | Xeon Gold 6314U | - |
| Intel | Xeon Gold 6326 | - |
| Intel | Xeon Gold 6328H | - |
| Intel | Xeon Gold 6328Hl | - |
| Intel | Xeon Gold 6330 | - |
| Intel | Xeon Gold 6330H | - |
Related Weaknesses (CWE)
References
- http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00737.hVendor Advisory
- http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00737.hVendor Advisory
FAQ
What is CVE-2022-29494?
CVE-2022-29494 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Improper input validation in firmware for OpenBMC in some Intel(R) platforms before versions egs-0.91-179 and bhs-04-45 may allow an authenticated user to potentially enable denial of service via netw...
How severe is CVE-2022-29494?
CVE-2022-29494 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-29494?
Check the references section above for vendor advisories and patch information. Affected products include: Intel Openbmc, Intel C621A, Intel C627A, Intel C629A, Intel Xeon Gold 5315Y.