Buffer overflow in Intel Server Board M10JNP2SB - CVE-2021-0113

 

Buffer overflow in Intel Server Board M10JNP2SB - CVE-2021-0113

Published: June 16, 2021


Vulnerability identifier: #VU54138
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-0113
CWE-ID: CWE-119
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error in the Baseboard Management Controller (BMC) firmware. A remote attacker on the local network can trigger memory corruption and cause a denial of service condition on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Intel Server Board M10JNP2SB

How to mitigate CVE-2021-0113

Install updates from vendor's website.

Intel Server Board M10JNP2SB - addressed in versions EFI BIOS 7215, BMC 8100.01.08

External References

Related Security Bulletins