CVE-2023-32280
Severity CVSS v4.0:
Pending analysis
Type:
CWE-522
Insufficiently Protected Credentials
Publication date:
14/02/2024
Last modified:
14/01/2026
Description
Insufficiently protected credentials in some Intel(R) Server Product OpenBMC firmware before versions egs-1.05 may allow an unauthenticated user to enable information disclosure via network access.
Impact
Base Score 3.x
5.30
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:intel:openbmc:*:*:*:*:*:*:*:* | egs-1.05 (excluding) | |
| cpe:2.3:h:intel:xeon_bronze_3408u:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:intel:xeon_gold_5403n:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:intel:xeon_gold_5411n:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:intel:xeon_gold_5412u:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:intel:xeon_gold_5415\+:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:intel:xeon_gold_5416s:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:intel:xeon_gold_5418n:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:intel:xeon_gold_5418y:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:intel:xeon_gold_5420\+:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:intel:xeon_gold_5423n:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:intel:xeon_gold_5433n:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:intel:xeon_gold_6403n:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:intel:xeon_gold_6414u:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:intel:xeon_gold_6416h:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



