CVE-2022-29494

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
16/02/2023
Last modified:
08/08/2023

Description

Improper input validation in firmware for OpenBMC in some Intel(R) platforms before versions egs-0.91-179 and bhs-04-45 may allow an authenticated user to potentially enable denial of service via network access.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:intel:openbmc:*:*:*:*:*:*:*:* wht-1.01-61_0.72 (excluding)
cpe:2.3:h:intel:c621a:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:c627a:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:c629a:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:xeon_gold_5315y:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:xeon_gold_5317:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:xeon_gold_5318h:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:xeon_gold_5318n:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:xeon_gold_5318s:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:xeon_gold_5318y:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:xeon_gold_5320:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:xeon_gold_5320h:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:xeon_gold_5320t:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:xeon_gold_6312u:-:*:*:*:*:*:*:*
cpe:2.3:h:intel:xeon_gold_6314u:-:*:*:*:*:*:*:*