#VU76717 Double Free in Intel Server Board Baseboard Management Controller (BMC) - CVE-2023-28411

 

#VU76717 Double Free in Intel Server Board Baseboard Management Controller (BMC) - CVE-2023-28411

Published: May 31, 2023


Vulnerability identifier: #VU76717
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2023-28411
CWE-ID: CWE-415
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
Intel Server Board Baseboard Management Controller (BMC)
Software vendor:
Intel

Description

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to a boundary error. A local administrator can pass specially crafted data to the application, trigger double free error and gain access to sensitive information on the target system.


Remediation

Install updates from vendor's website.

External links