CVE-2023-22297

Severity
7.8HIGH
EPSS
0.1%
top 74.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 10

Description

Access of memory location after end of buffer in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to enable escalation of privilege via local access.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HExploitability: 1.5 | Impact: 6.0

Patches

🔴Vulnerability Details

2
CVEList
CVE-2023-22297: Access of memory location after end of buffer in some Intel(R) Server Board BMC firmware before version 22023-05-10
GHSA
GHSA-v5rx-7rr8-5mq3: Access of memory location after end of buffer in some Intel(R) Server Board BMC firmware before version 22023-05-10