Information disclosure in Intel products - CVE-2023-25191
Published: April 5, 2025
Vulnerability identifier: #VU107012
CSH Severity: High
CVSS v4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-25191
CWE-ID: CWE-200
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by Redfish in AMI MegaRAC SPX devices. A remote attacker can obtain an administrative password and compromise the affected system.
Affected software
Intel Server Board M70KLP
Intel Server Board M10JNP2SB
Intel Server Board M20NTP
Intel Server Board M10JNP2SB
Intel Server Board M20NTP
How to mitigate CVE-2023-25191
Install updates from vendor's website.
Intel Server Board M70KLP - update to 4.16
Intel Server Board M10JNP2SB - update to 7.220
Intel Server Board M20NTP - update to 0027.D02
Intel Server Board M10JNP2SB - update to 7.220
Intel Server Board M20NTP - update to 0027.D02