CVE-2023-22297
published 2023-05-10CVE-2023-22297: Access of memory location after end of buffer in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to enable escalation…
PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.20%
10.1th percentile
Access of memory location after end of buffer in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to enable escalation of privilege via local access.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| intel | server_system_d50tnp1mhcpac_firmware | < 2.90 | 2.90 |
| intel | server_system_d50tnp1mhcrac_firmware | < 2.90 | 2.90 |
| intel | server_system_d50tnp1mhcrlc_firmware | < 2.90 | 2.90 |
| intel | server_system_d50tnp2mfalac_firmware | < 2.90 | 2.90 |
| intel | server_system_d50tnp2mhstac_firmware | < 2.90 | 2.90 |
| intel | server_system_d50tnp2mhsvac_firmware | < 2.90 | 2.90 |
| intel | server_system_m50cyp1ur204_firmware | < 2.90 | 2.90 |
| intel | server_system_m50cyp1ur212_firmware | < 2.90 | 2.90 |
| intel | server_system_m50cyp2ur208_firmware | < 2.90 | 2.90 |
| intel | server_system_m50cyp2ur312_firmware | < 2.90 | 2.90 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-05-10
Published