Input validation error in Intel Server Board M10JNP2SB - CVE-2021-0070

 

Input validation error in Intel Server Board M10JNP2SB - CVE-2021-0070

Published: June 16, 2021


Vulnerability identifier: #VU54137
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-0070
CWE-ID: CWE-20
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to escalate privileges on the system.

The vulnerability exists due to insufficient validation of user-supplied input in the Baseboard Management Controller (BMC) firmware. A remote attacker on the local network can pass specially crafted input to the application and gain elevated privileges on the target system.


Affected software

Intel Server Board M10JNP2SB

How to mitigate CVE-2021-0070

Install updates from vendor's website.

Intel Server Board M10JNP2SB - addressed in versions EFI BIOS 7215, BMC 8100.01.08

External References

Related Security Bulletins