Baseboard Management Controller Firmware

Vendor:

First CVE: Nov 14, 2019 · Active for 6 years

17
Total CVEs
More Total CVEs than 93% of tracked products
5.7
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 45% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Baseboard Management Controller Firmware over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 14, 2019
6 years ago
Most Recent CVE
Feb 16, 2023
1,255 days ago

CVE Severity & Scoring

Baseboard Management Controller Firmware17 CVEs
All CVEs352,708 CVEs
MediumHighCritical
Attack Vector
Local5 (29.4%)
Network11 (64.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (5.9%)
Attack Complexity
Low17 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None17 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low8 (47.1%)
High1 (5.9%)
None8 (47.1%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Heap corruption in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable information disclosure, escalation of privilege and/or
Nov 14, 20199.828NONO
Insufficient session validation in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable information disclosure and/or denial of
Nov 14, 20199.125NONO
Stack overflow in Intel(R) Baseboard Management Controller firmware may allow an authenticated user to potentially enable information disclosure and/or denial of service via networ
Nov 14, 20198.124NONO
Buffer overflow in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.48.ce3e3bd2 may allow an authenticated user to potentially
Jun 9, 20218.023NONO
Out of bounds write in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.48.ce3e3bd2 may allow an authenticated user to potentia
Jun 9, 20217.823NONO
Memory corruption in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable denial of service via network access.
Nov 14, 20197.523NONO
Out of bound read in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable escalation of privilege via network access.
Nov 14, 20197.823NONO
Insufficient input validation in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable denial of service via network access.
Nov 14, 20197.523NONO
Unhandled exception in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable denial of service via network access.
Nov 14, 20197.523NONO
Insufficient input validation in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable denial of service via network access.
Nov 14, 20197.523NONO

Exploit Exposure

Signals from CVEs in this product scope (17 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (17 CVEs).

Media Mentions

Signals from CVEs in this product scope (17 CVEs).

Top CNAs Publishing CVEs For Baseboard Management Controller Firmware

Top CWEs

Versions

No cataloged versions.