CVE-2023-31189

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
14/02/2024
Last modified:
14/01/2026

Description

Improper authentication in some Intel(R) Server Product OpenBMC firmware before version egs-1.09 may allow an authenticated user to enable escalation of privilege via local access.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:intel:openbmc:*:*:*:*:*:*:*:* egs-1.09 (excluding)
cpe:2.3:h:intel:xeon_bronze_3408u:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:xeon_gold_5403n:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:xeon_gold_5411n:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:xeon_gold_5412u:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:xeon_gold_5415\+:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:xeon_gold_5416s:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:xeon_gold_5418n:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:xeon_gold_5418y:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:xeon_gold_5420\+:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:xeon_gold_5423n:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:xeon_gold_5433n:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:xeon_gold_6403n:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:xeon_gold_6414u:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:xeon_gold_6416h:-:*:*:*:*:*:*:*