PT-2021-1985 · Intel · Intel Server Systems+2
Published
2021-02-09
·
Updated
2021-02-22
·
CVE-2020-12376
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Intel Server Boards, Server Systems and Compute Modules versions prior to 2.47
Description
The issue is related to the use of a hard-coded key in the BMC firmware, which may allow an authenticated user to potentially enable information disclosure via local access. This could lead to unauthorized access to protected information.
Recommendations
For versions prior to 2.47, update to version 2.47 or later to resolve the issue. As a temporary workaround, consider restricting local access to the BMC firmware to minimize the risk of exploitation.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Intel Compute Modules
Intel Server Boards
Intel Server Systems