Improper authentication in some Intel(R) Server Product OpenBMC firmware before version egs-1.09 may allow an authenticated user to enable escalation of privilege via local access.
oryginał ENCVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:NIntel Openbmc
OSIntel< egs-1.09Intel Xeon Bronze 3408u
HWIntelwszystkie wersjeIntel Xeon Gold 5403n
HWIntelwszystkie wersjeIntel Xeon Gold 5411n
HWIntelwszystkie wersjeIntel Xeon Gold 5412u
HWIntelwszystkie wersjeIntel Xeon Gold 5415\+
HWIntelwszystkie wersjeIntel Xeon Gold 5416s
HWIntelwszystkie wersjeIntel Xeon Gold 5418n
HWIntelwszystkie wersjeIntel Xeon Gold 5418y
HWIntelwszystkie wersjeIntel Xeon Gold 5420\+
HWIntelwszystkie wersjeIntel Xeon Gold 5423n
HWIntelwszystkie wersjeIntel Xeon Gold 5433n
HWIntelwszystkie wersjeIntel Xeon Gold 6403n
HWIntelwszystkie wersjeIntel Xeon Gold 6414u
HWIntelwszystkie wersjeIntel Xeon Gold 6416h
HWIntelwszystkie wersjeIntel Xeon Gold 6418h
HWIntelwszystkie wersjeIntel Xeon Gold 6421n
HWIntelwszystkie wersjeIntel Xeon Gold 6423n
HWIntelwszystkie wersjeIntel Xeon Gold 6426y
HWIntelwszystkie wersjeIntel Xeon Gold 6428n
HWIntelwszystkie wersjeIntel Xeon Gold 6430
HWIntelwszystkie wersjeIntel Xeon Gold 6433n
HWIntelwszystkie wersjeIntel Xeon Gold 6433ne
HWIntelwszystkie wersjeIntel Xeon Gold 6434
HWIntelwszystkie wersjeIntel Xeon Gold 6434h
HWIntelwszystkie wersjeIntel Xeon Gold 6438m
HWIntelwszystkie wersjeIntel Xeon Gold 6438n
HWIntelwszystkie wersjeIntel Xeon Gold 6438y\+
HWIntelwszystkie wersjeIntel Xeon Gold 6442y
HWIntelwszystkie wersjeIntel Xeon Gold 6443n
HWIntelwszystkie wersje
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
Tagi
Auth Bypass
CWE
Powiązane podatności
CVE-2026-20898HIGH8.5ten sam produkt
Improper access control in the firmware for some in Alias Checking Trusted Module for some Intel(R) Xeon(R) pr...
CVE-2026-20885HIGH7.0ten sam produkt
Improper authentication in the Intel(R) TDX module for some Intel(R) platforms within Ring 0: Trust Domain may...
CVE-2026-20775MEDIUM6.8ten sam produkt
Uncaught exception for some Intel(R) TDX modules within Ring 0: Trust Domain may allow a denial of service. Sy...
CVE-2026-20705MEDIUM6.8ten sam produkt
Insecure storage of sensitive information in the Intel(R) TDX module for some Intel(R) platform within Ring 0:...
CVE-2026-20901MEDIUM4.0ten sam produkt
Improper input validation for some Intel(R) Xeon(R) processors within firmware may allow an escalation of priv...