Intel Server Board S2600St Firmware vulnerabilities

25 known vulnerabilities affecting intel/server_board_s2600st_firmware.

Total CVEs
25
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH17MEDIUM8

Vulnerabilities

Page 2 of 2
CVE-2020-8717MEDIUMCVSS 5.5fixed in 1.592020-08-13
CVE-2020-8717 [MEDIUM] CWE-20 CVE-2020-8717: Improper input validation in a subsystem for some Intel Server Boards, Server Systems and Compute Mo Improper input validation in a subsystem for some Intel Server Boards, Server Systems and Compute Modules before version 1.59 may allow an authenticated user to potentially enable denial of service via local access.
nvd
CVE-2020-8723MEDIUMCVSS 6.3fixed in 1.592020-08-13
CVE-2020-8723 [MEDIUM] CWE-79 CVE-2020-8723: Cross-site scripting for some Intel(R) Server Boards, Server Systems and Compute Modules before vers Cross-site scripting for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.
nvd
CVE-2020-8710MEDIUMCVSS 6.7fixed in 2.452020-08-13
CVE-2020-8710 [MEDIUM] CWE-120 CVE-2020-8710: Buffer overflow in the bootloader for some Intel(R) Server Boards, Server Systems and Compute Module Buffer overflow in the bootloader for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.45 may allow a privileged user to potentially enable escalation of privilege via local access.
nvd
CVE-2020-8715MEDIUMCVSS 5.5fixed in 1.592020-08-13
CVE-2020-8715 [MEDIUM] CWE-763 CVE-2020-8715: Invalid pointer for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1 Invalid pointer for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow an unauthenticated user to potentially enable denial of service via local access.
nvd
CVE-2018-12173HIGHCVSS 7.6fixed in 00.01.00142018-10-10
CVE-2018-12173 [HIGH] CWE-732 CVE-2018-12173: Insufficient access protection in firmware in Intel Server Board, Intel Server System and Intel Comp Insufficient access protection in firmware in Intel Server Board, Intel Server System and Intel Compute Module before firmware version 00.01.0014 may allow an unauthenticated attacker to potentially execute arbitrary code resulting in information disclosure, escalation of privilege and/or denial of service via local access.
nvd