Known vulnerabilities in Intel Server Platform Services Firmware
Vendor:
Intel
Software:
Intel Server Platform Services Firmware
Software CPE:
cpe:2.3:a:intel:intel_sps:*:*:*:*:*:*:*:*
Website:
https://www.intel.com
Total vulnerabilities:
21
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.4
Breakdown by Severity Chart
SPS_E5_06.01.04.059.0
SPS_E5_06.01.02.048.0
SPS_E5_04.04.04.500.0
SPS_E5_06.01.04.002.0
SPS_E3_06.00.03.300.0
SPS_E5_04.04.04.300.0
SPS_E3_06.00.03.035.0
SPS_E3_04.01.04.700.0
SPS_E3_04.01.04.530.0
SPS_E3_04.08.04.330.0
SPS_E5_04.04.03.263.0
SPS_SoC-A_05.00.03.091.0
SPS_E3_05.01.04.300.0
SPS_SoC-A_05.00.03.098.0
SPS_E5_04.04.03.228.0
SPS_E5_04.04.04.023.0
SoC-A_04.00.04.300
SoC-X_04.00.04.200
E3_04.01.04.200
E5_04.01.04.400
E3_05.01.04.200
SPS_SoC-A_04.00.04.211.0
SPS_SoC-X_04.00.04.128.0
SPS_E5_04.01.04.380.0
SPS_E3_04.08.04.070.0
SPS_E3_04.01.04.109.0
SPS_E3_04.01.04.086.0
SPS_E3_04.01.04.085.0
SPS_E3_04.01.00.000.0
SPS_SoC-A_04.00.04.191.0
SPS_SoC-A_04.00.04.190.0
SPS_SoC-A_04.00.00.000.0
SPS_SoC-X_04.00.04.108.0
SPS_SoC-X_04.00.04.107.0
SPS_SoC-X_04.00.00.000.0
SPS_E5_04.01.04.305.0
SPS_E5_04.01.04.304.0
SPS_E5_04.00.00.000.0
4.0
Vulnerabilities (21)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU103984 - Improper input validation CVE-2024-25571 |
CWE-20 | Low | SPS_E5_06.01.04.059.0 | 14.02.2025 |
SB2025021437 SB2025051942 SB2025052089 and 2 more |
||
| #VU87496 - Resource exhaustion CVE-2023-35191 |
CWE-400 | Low | SPS_E5_04.04.04.500.0, SPS_E5_06.01.02.048.0 | 13.03.2024 |
SB2024031383 SB2024082109 SB2025032425 and 4 more |
||
| #VU86957 - Untrusted Search Path CVE-2023-29153 |
CWE-426 | Low | SPS_E5_06.01.04.002.0 | 01.03.2024 |
SB2024030147 SB20240731206 SB2024080116 |
||
| #VU72465 - Improper Handling of Exceptional Conditions CVE-2022-36794 |
CWE-755 | Low | SPS_E3_06.00.03.300.0, SPS_E5_04.04.04.300.0 | 21.02.2023 |
SB2023022162 SB2023022190 SB2023031307 and 2 more |
||
| #VU72464 - Exposed Dangerous Method or Function CVE-2022-36348 |
CWE-749 | Low | SPS_E3_06.00.03.300.0, SPS_E5_04.04.04.300.0 | 21.02.2023 |
SB2023022162 SB2023022190 SB2023030710 and 7 more |
||
| #VU69317 - Improper input validation CVE-2022-29515 |
CWE-20 | Low | SPS_E3_04.01.04.700.0, SPS_E3_06.00.03.035.0 | 15.11.2022 |
SB2022111522 SB2023031313 SB2023081531 |
||
| #VU69316 - Improper input validation CVE-2022-29466 |
CWE-20 | Low | SPS_E3_04.01.04.700.0, SPS_E3_06.00.03.035.0 | 15.11.2022 |
SB2022111522 SB2023010502 SB2023031313 and 1 more |
||
| #VU66486 - Incomplete cleanup CVE-2022-26074 |
CWE-459 | Low | SPS_E3_04.01.04.530.0, SPS_E3_04.08.04.330.0 | 15.08.2022 |
SB2022081518 SB2023081531 |
||
| #VU54199 - Out-of-bounds read CVE-2020-24506 |
CWE-125 | Low | SPS_E3_05.01.04.300.0, SPS_SoC-A_05.00.03.091.0, SPS_E5_04.04.03.263.0, SPS_E5_04.04.04.023.0 | 17.06.2021 |
SB2021061712 SB2021081109 SB2022111726 and 1 more |
||
| #VU54198 - Memory corruption CVE-2020-8703 |
CWE-119 | Low | SPS_E3_05.01.04.300.0, SPS_SoC-A_05.00.03.091.0, SPS_E5_04.04.03.263.0, SPS_E5_04.04.04.023.0 | 17.06.2021 |
SB2021061712 SB2021081109 SB2022111726 |
||
| #VU54197 - Permissions, Privileges, and Access Controls CVE-2020-24516 |
CWE-264 | Low | SPS_E3_05.01.04.300.0, SPS_SoC-A_05.00.03.091.0, SPS_E5_04.04.03.263.0, SPS_E5_04.04.04.023.0 | 17.06.2021 |
SB2021061712 |
||
| #VU54196 - Exposure of sensitive information to an unauthorized actor CVE-2020-24507 |
CWE-200 | Low | SPS_E3_05.01.04.300.0, SPS_SoC-A_05.00.03.091.0, SPS_E5_04.04.03.263.0, SPS_E5_04.04.04.023.0 | 17.06.2021 |
SB2021061712 SB2021081109 SB2022111726 and 1 more |
||
| #VU54195 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CVE-2020-8704 |
CWE-362 | Low | SPS_E3_05.01.04.300.0, SPS_SoC-A_05.00.03.091.0, SPS_E5_04.04.03.263.0, SPS_E5_04.04.04.023.0 | 17.06.2021 |
SB2021061712 SB2021081109 SB2023032421 |
||
| #VU54194 - Permissions, Privileges, and Access Controls CVE-2020-24509 |
CWE-264 | Low | SPS_E3_05.01.04.300.0, SPS_SoC-A_05.00.03.091.0, SPS_E5_04.04.03.263.0, SPS_E5_04.04.04.023.0 | 17.06.2021 |
SB2021061712 SB2022111726 |
||
| #VU54101 - Improper input validation CVE-2021-0051 |
CWE-20 | Low | SPS_SoC-A_05.00.03.098.0, SPS_E5_04.04.03.228.0, SPS_E5_04.04.04.023.0 | 14.06.2021 |
SB2021061410 |
||
| #VU48680 - Improper Initialization CVE-2020-8744 |
CWE-665 | Low | E3_05.01.04.200 | 12.11.2020 |
SB2020112614 SB2021051312 |
||
| #VU48681 - Improper Initialization CVE-2020-8705 |
CWE-665 | Low | SoC-A_04.00.04.300, SoC-X_04.00.04.200, E3_04.01.04.200, E3_05.01.04.200, E5_04.01.04.400 | 12.11.2020 |
SB2020112616 |
||
| #VU29001 - Integer overflow CVE-2020-0545 |
CWE-190 | Low | SPS_E3_04.01.04.109.0, SPS_E3_04.08.04.070.0, SPS_SoC-X_04.00.04.128.0, SPS_SoC-A_04.00.04.211.0, SPS_E5_04.01.04.380.0 | 12.06.2020 |
SB2020061207 SB2022102726 |
||
| #VU28973 - Improper Initialization CVE-2020-0586 |
CWE-665 | Low | SPS_E3_04.01.04.109.0, SPS_E3_04.08.04.070.0 | 11.06.2020 |
SB2020061114 |
||
| #VU9389 - Buffer overflow CVE-2017-5709 |
CWE-120 | Low | - | 22.11.2017 |
SB2017112201 SB2017112202 SB2018030203 |
Showing elements 1 - 20 out of 21