CVE-2023-31276

CVSS 3.1 Score 8.2 of 10 (high)

Details

Published Feb 12, 2025
CWE ID 122

Summary

CVE-2023-31276 is a heap-based buffer overflow vulnerability affecting the BMC Firmware of Intel server boards S2600WF, S2600ST, S2600BP, before version 02.01.0017, and M50CYP, D50TNP before version R01.01.0009. This issue allows a privileged user with local access to exploit the buffer overflow and escalate their privileges, potentially gaining unauthorized access to critical system functions. By manipulating specially crafted input data, an attacker can cause the firmware to write beyond the allocated heap memory, leading to erratic behavior and potential code execution. Users are strongly advised to update their firmware to the latest version to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share