CVE-2020-5633

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
13/01/2021
Last modified:
21/01/2021

Description

Multiple NEC products (Express5800/T110j, Express5800/T110j-S, Express5800/T110j (2nd-Gen), Express5800/T110j-S (2nd-Gen), iStorage NS100Ti, and Express5800/GT110j) where Baseboard Management Controller (BMC) firmware Rev1.09 and earlier is applied allows remote attackers to bypass authentication and then obtain/modify BMC setting information, obtain monitoring information, or reboot/shut down the vulnerable product via unspecified vectors.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:nec:baseboard_management_controller:*:*:*:*:*:*:*:* 1.09 (including)
cpe:2.3:h:nec:express5800\/gt110j:-:*:*:*:*:*:*:*
cpe:2.3:h:nec:express5800\/t110j:-:*:*:*:*:*:*:*
cpe:2.3:h:nec:express5800\/t110j-s:-:*:*:*:*:*:*:*
cpe:2.3:h:nec:express5800\/t110j-s_\(2nd-gen\):-:*:*:*:*:*:*:*
cpe:2.3:h:nec:express5800\/t110j_\(2nd-gen\):-:*:*:*:*:*:*:*
cpe:2.3:h:nec:istorage_ns100ti:-:*:*:*:*:*:*:*