CVE-2020-26122 describes a remote code execution vulnerability affecting Inspur NF5266M5 servers (through version 3.21.2) and other M5 series devices. The vulnerability stems from insufficient firmware verification and a lack of signature validation within the Baseboard Management Controller (BMC) program. An attacker with administrator privileges can exploit this weakness to insert malicious code into the firmware, bypass existing verification, and gain control of the BMC. This high-severity vulnerability (CVSS 7.2) allows for complete compromise of confidentiality, integrity, and availability, with a low attack complexity. While no public exploits or active exploitation have been observed, and community discussion is minimal, the potential impact remains significant for affected systems.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.19.34CPE matchmatch criteria | cpe:2.3:o:inspur:nf8480m5_firmware:*:*:*:*:*:*:*:* | ||
< 1.19.34CPE matchmatch criteria | cpe:2.3:o:inspur:nf8260m5_firmware:*:*:*:*:*:*:*:* | ||
< 4.5.3CPE matchmatch criteria | cpe:2.3:o:inspur:ns5162m5_firmware:*:*:*:*:*:*:*:* | ||
< 1.19.33CPE matchmatch criteria | cpe:2.3:o:inspur:ns5488m5_firmware:*:*:*:*:*:*:*:* | ||
< 1.19.33CPE matchmatch criteria | cpe:2.3:o:inspur:ns5484m5_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.