CVE-2019-11168
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
14/11/2019
Last modified:
17/06/2026
Description
Insufficient session validation in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable information disclosure and/or denial of service via network access.
Impact
Base Score 3.x
9.10
Severity 3.x
CRITICAL
Base Score 2.0
6.40
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:intel:baseboard_management_controller_firmware:*:*:*:*:*:*:*:* | 2.18 (excluding) | |
| cpe:2.3:h:intel:bbs2600bpb:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:intel:bbs2600bpbr:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:intel:bbs2600bpq:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:intel:bbs2600bpqr:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:intel:bbs2600bps:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:intel:bbs2600bpsr:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:intel:bbs2600stb:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:intel:bbs2600stbr:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:intel:bbs2600stq:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:intel:bbs2600stqr:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:intel:hns2600bpb:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:intel:hns2600bpb24:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:intel:hns2600bpb24r:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:intel:hns2600bpb24rx:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://support.f5.com/csp/article/K64346530?utm_source=f5support&%3Butm_medium=RSS
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00313.html
- https://support.f5.com/csp/article/K64346530?utm_source=f5support&%3Butm_medium=RSS
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00313.html



