Information disclosure in Intel products - CVE-2023-25192
Published: April 5, 2025
Vulnerability identifier: #VU107013
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-25192
CWE-ID: CWE-200
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to enumerate user accounts
The vulnerability exists due to excessive data output by Redfish. A remote attacker can enumerate user accounts.
Affected software
Intel Server Board M70KLP
Intel Server Board M10JNP2SB
Intel Server Board M20NTP
Intel Server Board M10JNP2SB
Intel Server Board M20NTP
How to mitigate CVE-2023-25192
Install updates from vendor's website.
Intel Server Board M70KLP - update to 4.16
Intel Server Board M10JNP2SB - update to 7.220
Intel Server Board M20NTP - update to 0027.D02
Intel Server Board M10JNP2SB - update to 7.220
Intel Server Board M20NTP - update to 0027.D02