HIGH · 8.2

CVE-2023-22297

Access of memory location after end of buffer in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to enable escalation of privilege via local access.

Vulnerability Description

Access of memory location after end of buffer in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to enable escalation of privilege via local access.

CVSS Score

8.2

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
IntelServer System D50Tnp1Mhcrlc Firmware< 2.90
IntelServer System D50Tnp1Mhcrlc-
IntelServer System D50Tnp1Mhcpac Firmware< 2.90
IntelServer System D50Tnp1Mhcpac-
IntelServer System D50Tnp2Mhsvac Firmware< 2.90
IntelServer System D50Tnp2Mhsvac-
IntelServer System D50Tnp2Mhstac Firmware< 2.90
IntelServer System D50Tnp2Mhstac-
IntelServer System D50Tnp1Mhcrac Firmware< 2.90
IntelServer System D50Tnp1Mhcrac-
IntelServer System D50Tnp2Mfalac Firmware< 2.90
IntelServer System D50Tnp2Mfalac-
IntelServer System M50Cyp1Ur204 Firmware< 2.90
IntelServer System M50Cyp1Ur204-
IntelServer System M50Cyp1Ur212 Firmware< 2.90
IntelServer System M50Cyp1Ur212-
IntelServer System M50Cyp2Ur312 Firmware< 2.90
IntelServer System M50Cyp2Ur312-
IntelServer System M50Cyp2Ur208 Firmware< 2.90
IntelServer System M50Cyp2Ur208-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-22297?

CVE-2023-22297 is a vulnerability with a CVSS score of 8.2 (HIGH). Access of memory location after end of buffer in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to enable escalation of privilege via local access.

How severe is CVE-2023-22297?

CVE-2023-22297 has been rated HIGH with a CVSS base score of 8.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-22297?

Check the references section above for vendor advisories and patch information. Affected products include: Intel Server System D50Tnp1Mhcrlc Firmware, Intel Server System D50Tnp1Mhcrlc, Intel Server System D50Tnp1Mhcpac Firmware, Intel Server System D50Tnp1Mhcpac, Intel Server System D50Tnp2Mhsvac Firmware.