Vulnerability Description
Buffer overflow in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to enable escalation of privilege via local access.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Intel | Server System D50Tnp1Mhcrlc Firmware | < 2.90 |
| Intel | Server System D50Tnp1Mhcrlc | - |
| Intel | Server System D50Tnp1Mhcpac Firmware | < 2.90 |
| Intel | Server System D50Tnp1Mhcpac | - |
| Intel | Server System D50Tnp2Mhsvac Firmware | < 2.90 |
| Intel | Server System D50Tnp2Mhsvac | - |
| Intel | Server System D50Tnp2Mhstac Firmware | < 2.90 |
| Intel | Server System D50Tnp2Mhstac | - |
| Intel | Server System D50Tnp1Mhcrac Firmware | < 2.90 |
| Intel | Server System D50Tnp1Mhcrac | - |
| Intel | Server System D50Tnp2Mfalac Firmware | < 2.90 |
| Intel | Server System D50Tnp2Mfalac | - |
| Intel | Server System M50Cyp1Ur204 Firmware | < 2.90 |
| Intel | Server System M50Cyp1Ur204 | - |
| Intel | Server System M50Cyp1Ur212 Firmware | < 2.90 |
| Intel | Server System M50Cyp1Ur212 | - |
| Intel | Server System M50Cyp2Ur312 Firmware | < 2.90 |
| Intel | Server System M50Cyp2Ur312 | - |
| Intel | Server System M50Cyp2Ur208 Firmware | < 2.90 |
| Intel | Server System M50Cyp2Ur208 | - |
Related Weaknesses (CWE)
References
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00839.PatchVendor Advisory
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00839.PatchVendor Advisory
FAQ
What is CVE-2023-22661?
CVE-2023-22661 is a vulnerability with a CVSS score of 8.2 (HIGH). Buffer overflow in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to enable escalation of privilege via local access.
How severe is CVE-2023-22661?
CVE-2023-22661 has been rated HIGH with a CVSS base score of 8.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-22661?
Check the references section above for vendor advisories and patch information. Affected products include: Intel Server System D50Tnp1Mhcrlc Firmware, Intel Server System D50Tnp1Mhcrlc, Intel Server System D50Tnp1Mhcpac Firmware, Intel Server System D50Tnp1Mhcpac, Intel Server System D50Tnp2Mhsvac Firmware.