MEDIUM✓ PATCH🇵🇱 Wersja polska

CVE-2023-32280

CVSS 5.3v3.1pub. 2024-02-14upd. 2026-01-14

Insufficiently protected credentials in some Intel(R) Server Product OpenBMC firmware before versions egs-1.05 may allow an unauthenticated user to enable information disclosure via network access.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
  • Intel Openbmc

    OS
    Intel
    < egs-1.05
  • Intel Xeon Bronze 3408u

    HW
    Intel
    all versions
  • Intel Xeon Gold 5403n

    HW
    Intel
    all versions
  • Intel Xeon Gold 5411n

    HW
    Intel
    all versions
  • Intel Xeon Gold 5412u

    HW
    Intel
    all versions
  • Intel Xeon Gold 5415\+

    HW
    Intel
    all versions
  • Intel Xeon Gold 5416s

    HW
    Intel
    all versions
  • Intel Xeon Gold 5418n

    HW
    Intel
    all versions
  • Intel Xeon Gold 5418y

    HW
    Intel
    all versions
  • Intel Xeon Gold 5420\+

    HW
    Intel
    all versions
  • Intel Xeon Gold 5423n

    HW
    Intel
    all versions
  • Intel Xeon Gold 5433n

    HW
    Intel
    all versions
  • Intel Xeon Gold 6403n

    HW
    Intel
    all versions
  • Intel Xeon Gold 6414u

    HW
    Intel
    all versions
  • Intel Xeon Gold 6416h

    HW
    Intel
    all versions
  • Intel Xeon Gold 6418h

    HW
    Intel
    all versions
  • Intel Xeon Gold 6421n

    HW
    Intel
    all versions
  • Intel Xeon Gold 6423n

    HW
    Intel
    all versions
  • Intel Xeon Gold 6426y

    HW
    Intel
    all versions
  • Intel Xeon Gold 6428n

    HW
    Intel
    all versions
  • Intel Xeon Gold 6430

    HW
    Intel
    all versions
  • Intel Xeon Gold 6433n

    HW
    Intel
    all versions
  • Intel Xeon Gold 6433ne

    HW
    Intel
    all versions
  • Intel Xeon Gold 6434

    HW
    Intel
    all versions
  • Intel Xeon Gold 6434h

    HW
    Intel
    all versions
  • Intel Xeon Gold 6438m

    HW
    Intel
    all versions
  • Intel Xeon Gold 6438n

    HW
    Intel
    all versions
  • Intel Xeon Gold 6438y\+

    HW
    Intel
    all versions
  • Intel Xeon Gold 6442y

    HW
    Intel
    all versions
  • Intel Xeon Gold 6443n

    HW
    Intel
    all versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2023-31189MEDIUM5.2same product

Improper authentication in some Intel(R) Server Product OpenBMC firmware before version egs-1.09 may allow an ...

CVE-2022-29494MEDIUM6.5same product

Improper input validation in firmware for OpenBMC in some Intel(R) platforms before versions egs-0.91-179 and ...

CVE-2021-45046CRITICAL9.0⚠ KEVPL ✓same vendor

Apache Log4j: niekompletna naprawa CVE-2021-44228 — RCE przez JNDI Lookup

CVE-2021-44228CRITICAL10.0⚠ KEVPL ✓same vendor

Apache Log4j2 Log4Shell — RCE przez podatną funkcję JNDI lookup

CVE-2017-5689CRITICAL9.8⚠ KEVPL ✓same vendor

Privilege Escalation w Intel AMT/ISM/SBT — nieautoryzowany dostęp systemowy