CVE-2020-12376

MEDIUM

Intel BMC Firmware < 2.47 - Authenticated Information Disclosure via Hard-coded Key

Title source: llm
STIX 2.1

Description

Use of hard-coded key in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.47 may allow authenticated user to potentially enable information disclosure via local access.

References (1)

Core 1
Core References

Scores

CVSS v3 5.5
EPSS 0.0005
EPSS Percentile 16.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-798
Status published
Products (1)
intel/bmc_firmware < 2.47
Published Feb 17, 2021
Tracked Since Feb 18, 2026