Intel Xeon Baseboard Management Component (BMC) Privilege Escalation (INTEL-SA-00026)

medium Nessus Plugin ID 70094

Synopsis

The remote device is affected by a privilege escalation vulnerability.

Description

The version of the Intel BIOS on the remote device indicates that the Baseboard Management Component (BMC) firmware it is running is affected by an unspecified privilege escalation vulnerability.

A knowledgeable remote malicious attacker could leverage this issue to deny service to legitimate users.

Solution

Upgrade to the relevant BIOS and BMC firmware referenced in the vendor's advisory.

See Also

http://www.nessus.org/u?5d5284b6

Plugin Details

Severity: Medium

ID: 70094

File Name: intel_sa_00026.nasl

Version: 1.5

Type: local

Family: Misc.

Published: 9/24/2013

Updated: 6/3/2021

Supported Sensors: Nessus

Risk Information

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Information

Required KB Items: BIOS/Version, BIOS/Vendor

Exploit Ease: No known exploits are available

Patch Publication Date: 11/1/2010

Vulnerability Publication Date: 11/1/2010

Reference Information

BID: 44592

IAVB: 2010-B-0098-S