CVE Feed

    Dashboard / CVE / CVE-2023-31189

    CVE-2023-31189

    Improper authentication in some Intel(R) Server Product OpenBMC firmware before version egs-1.09 may allow an authenticated user to enable escalation of privilege via local access.

    Published:Feb 14, 2024
    Last Modified:Jan 14, 2026
    EPS:Feb 14, 2024
    EPSS Score:0.00066
    CVSS Score:5.2

    Affected Products

    Vendor
    Intel
    Product
    Openbmc
    Vendor
    Intel
    Product
    Xeon Bronze 3408u
    Vendor
    Intel
    Product
    Xeon Gold 5403n
    Vendor
    Intel
    Product
    Xeon Gold 5411n
    Vendor
    Intel
    Product
    Xeon Gold 5412u
    Vendor
    Intel
    Product
    Xeon Gold 5415\+
    Vendor
    Intel
    Product
    Xeon Gold 5416s
    Vendor
    Intel
    Product
    Xeon Gold 5418n
    Vendor
    Intel
    Product
    Xeon Gold 5418y
    Vendor
    Intel
    Product
    Xeon Gold 5420\+
    Vendor
    Intel
    Product
    Xeon Gold 5423n
    Vendor
    Intel
    Product
    Xeon Gold 5433n
    Vendor
    Intel
    Product
    Xeon Gold 6403n
    Vendor
    Intel
    Product
    Xeon Gold 6414u
    Vendor
    Intel
    Product
    Xeon Gold 6416h
    Vendor
    Intel
    Product
    Xeon Gold 6418h
    Vendor
    Intel
    Product
    Xeon Gold 6421n
    Vendor
    Intel
    Product
    Xeon Gold 6423n
    Vendor
    Intel
    Product
    Xeon Gold 6426y
    Vendor
    Intel
    Product
    Xeon Gold 6428n
    Vendor
    Intel
    Product
    Xeon Gold 6430
    Vendor
    Intel
    Product
    Xeon Gold 6433n
    Vendor
    Intel
    Product
    Xeon Gold 6433ne
    Vendor
    Intel
    Product
    Xeon Gold 6434
    Vendor
    Intel
    Product
    Xeon Gold 6434h
    Vendor
    Intel
    Product
    Xeon Gold 6438m
    Vendor
    Intel
    Product
    Xeon Gold 6438n
    Vendor
    Intel
    Product
    Xeon Gold 6438y\+
    Vendor
    Intel
    Product
    Xeon Gold 6442y
    Vendor
    Intel
    Product
    Xeon Gold 6443n
    Vendor
    Intel
    Product
    Xeon Gold 6444y
    Vendor
    Intel
    Product
    Xeon Gold 6448h
    Vendor
    Intel
    Product
    Xeon Gold 6448y
    Vendor
    Intel
    Product
    Xeon Gold 6454s
    Vendor
    Intel
    Product
    Xeon Gold 6458q
    Vendor
    Intel
    Product
    Xeon Platinum 8444h
    Vendor
    Intel
    Product
    Xeon Platinum 8450h
    Vendor
    Intel
    Product
    Xeon Platinum 8452y
    Vendor
    Intel
    Product
    Xeon Platinum 8454h
    Vendor
    Intel
    Product
    Xeon Platinum 8458p
    Vendor
    Intel
    Product
    Xeon Platinum 8460h
    Vendor
    Intel
    Product
    Xeon Platinum 8460y\+
    Vendor
    Intel
    Product
    Xeon Platinum 8461v
    Vendor
    Intel
    Product
    Xeon Platinum 8462y\+
    Vendor
    Intel
    Product
    Xeon Platinum 8468
    Vendor
    Intel
    Product
    Xeon Platinum 8468h
    Vendor
    Intel
    Product
    Xeon Platinum 8468v
    Vendor
    Intel
    Product
    Xeon Platinum 8470
    Vendor
    Intel
    Product
    Xeon Platinum 8470n
    Vendor
    Intel
    Product
    Xeon Platinum 8471n
    Vendor
    Intel
    Product
    Xeon Platinum 8480\+
    Vendor
    Intel
    Product
    Xeon Platinum 8490h
    Vendor
    Intel
    Product
    Xeon Silver 4410t
    Vendor
    Intel
    Product
    Xeon Silver 4410y

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High