PT-2020-5638 · Intel · Intel Modular Server Mfs2600Ki+1

Michael N. Henry

·

Published

2020-04-14

·

Updated

2021-07-21

·

CVE-2020-0577

CVSS v2.0

5.8

Medium

VectorAV:A/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Intel Modular Server MFS2600KISPP Compute Module (affected versions not specified) Intel Modular Server MFS2600KI (affected versions not specified)
Description The issue is related to insufficient control flow and a buffer copy without input size validation in the Intel Modular Server's firmware. This could potentially allow an unauthenticated user, with adjacent access, to escalate privileges. The vulnerability may also be exploited by a remote attacker to gain elevated privileges.
Recommendations For Intel Modular Server MFS2600KISPP Compute Module, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For Intel Modular Server MFS2600KI, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-01338
CVE-2020-0577

Affected Products

Intel Modular Server Mfs2600Ki
Intel Modular Server Mfs2600Kispp Compute Module