Double Free in Intel Server Board Baseboard Management Controller (BMC) - CVE-2023-28411

 

Double Free in Intel Server Board Baseboard Management Controller (BMC) - CVE-2023-28411

Published: May 31, 2023


Vulnerability identifier: #VU76717
CSH Severity: Low
CVSS v4: 2.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-28411
CWE-ID: CWE-415
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to a boundary error. A local administrator can pass specially crafted data to the application, trigger double free error and gain access to sensitive information on the target system.


Affected software

Intel Server Board Baseboard Management Controller (BMC)

How to mitigate CVE-2023-28411

Install updates from vendor's website.

Intel Server Board Baseboard Management Controller (BMC) - update to 2.90

External References

Related Security Bulletins