Use of hard-coded key in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.47 may allow authenticated user to potentially enable information disclosure via local access.
References
| Link | Resource |
|---|---|
| https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00434.html | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
Information
Published : 2021-02-17 14:15
Updated : 2021-02-22 20:43
NVD link : CVE-2020-12376
Mitre link : CVE-2020-12376
JSON object : View
Products Affected
intel
- hns2600bps
- hns2600bpbr
- hns2600bps24
- s2600bpsr
- r2312wftzs
- s2600wft
- hns2600bpb24
- r2308wftzsr
- hns2600bpb
- hns2600bps24r
- r2312wf0npr
- hns2600bpblc
- r1208wftysr
- r1304wftys
- s2600stb
- s2600wf0
- hns2600bpqr
- r2208wftzs
- r2312wftzsr
- r1304wftysr
- r1208wftys
- hns2600bpsr
- hns2600bpq24r
- r2208wfqzsr
- r2208wftzsr
- r2208wf0zs
- r2224wftzsr
- hns2600bpq
- r2308wftzs
- hns2600bpq24
- s2600bpqr
- s2600wfq
- r2208wf0zsr
- r1208wfqysr
- hns2600bpb24r
- r1000wf
- bmc_firmware
- r1304wf0ysr
- s2600stq
- s2600bpbr
- r2224wftzs
- r2224wfqzs
- r2312wfqzs
- r2312wf0np
- r1304wf0ys
- r2208wfqzs
- hns2600bpblc24
- hns2600bpblc24r
CWE
CWE-798
Use of Hard-coded Credentials
