Описание
The firmware for Intelligent Platform Management Interface (IPMI) 1.5-based Intel Server Boards and Platforms is shipped with an Authentication Type Enables parameter set to an invalid None parameter, which allows remote attackers to obtain sensitive information when LAN management functionality is enabled.
Ссылки
- Vendor Advisory
- PatchVendor Advisory
- Vendor Advisory
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:intel:cli_auto-configuration_utility:*:*:*:*:*:*:*:*
cpe:2.3:a:intel:client_system_setup_utility:*:*:*:*:*:*:*:*
cpe:2.3:a:intel:server_configuration_wizard:*:*:*:*:*:*:*:*
cpe:2.3:a:intel:server_control:*:*:*:*:*:*:*:*
cpe:2.3:a:intel:system_setup_utility:*:*:*:*:*:*:*:*
cpe:2.3:h:intel:carrier_grade_server_tigpr2u:*:*:*:*:*:*:*:*
cpe:2.3:h:intel:carrier_grade_server_tsrlt2:*:*:*:*:*:*:*:*
cpe:2.3:h:intel:carrier_grade_server_tsrmt2:*:*:*:*:*:*:*:*
Конфигурация 2
Одно из
cpe:2.3:h:hp:carrier_grade_server_cc2300:a6898a:*:*:*:*:*:*:*
cpe:2.3:h:hp:carrier_grade_server_cc2300:a6899a:*:*:*:*:*:*:*
cpe:2.3:h:hp:carrier_grade_server_cc3300:a6900a:*:*:*:*:*:*:*
cpe:2.3:h:hp:carrier_grade_server_cc3300:a6901a:*:*:*:*:*:*:*
cpe:2.3:h:hp:carrier_grade_server_cc3310:a9862a:*:*:*:*:*:*:*
cpe:2.3:h:hp:carrier_grade_server_cc3310:a9863a:*:*:*:*:*:*:*
cpe:2.3:h:intel:entry_server_board_se7210tp1-e:*:*:*:*:*:*:*:*
cpe:2.3:h:intel:entry_server_platform_sr1325tp1-e:*:*:*:*:*:*:*:*
cpe:2.3:h:intel:server_board_scb2:*:*:*:*:*:*:*:*
cpe:2.3:h:intel:server_board_sds2:*:*:*:*:*:*:*:*
cpe:2.3:h:intel:server_board_se7500wv2:*:*:*:*:*:*:*:*
cpe:2.3:h:intel:server_board_se7501hg2:*:*:*:*:*:*:*:*
cpe:2.3:h:intel:server_board_shg2:*:*:*:*:*:*:*:*
cpe:2.3:h:intel:server_platform_spsh4:*:*:*:*:*:*:*:*
cpe:2.3:h:intel:server_platform_sr870bh2:*:*:*:*:*:*:*:*
cpe:2.3:h:intel:server_platform_sr870bn4:*:*:*:*:*:*:*:*
cpe:2.3:h:intel:server_platform_srsh4:*:*:*:*:*:*:*:*
EPSS
Процентиль: 78%
0.01141
Низкий
5 Medium
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
почти 4 года назад
The firmware for Intelligent Platform Management Interface (IPMI) 1.5-based Intel Server Boards and Platforms is shipped with an Authentication Type Enables parameter set to an invalid None parameter, which allows remote attackers to obtain sensitive information when LAN management functionality is enabled.
EPSS
Процентиль: 78%
0.01141
Низкий
5 Medium
CVSS2
Дефекты
NVD-CWE-Other