CVE-2023-31189
Improper authentication in some Intel(R) Server Product OpenBMC firmware before version egs-1.09 may allow an authenticated user to enable escalation of privilege via local access.
Published:Feb 14, 2024
Last Modified:Jan 14, 2026
EPS:Feb 14, 2024
EPSS Score:0.00066
CVSS Score:5.2
Affected Products
Vendor
Product
Action
Vendor
Intel
Product
Openbmc
Intel
Openbmc
Vendor
Intel
Product
Xeon Bronze 3408u
Intel
Xeon Bronze 3408u
Vendor
Intel
Product
Xeon Gold 5403n
Intel
Xeon Gold 5403n
Vendor
Intel
Product
Xeon Gold 5411n
Intel
Xeon Gold 5411n
Vendor
Intel
Product
Xeon Gold 5412u
Intel
Xeon Gold 5412u
Vendor
Intel
Product
Xeon Gold 5415\+
Intel
Xeon Gold 5415\+
Vendor
Intel
Product
Xeon Gold 5416s
Intel
Xeon Gold 5416s
Vendor
Intel
Product
Xeon Gold 5418n
Intel
Xeon Gold 5418n
Vendor
Intel
Product
Xeon Gold 5418y
Intel
Xeon Gold 5418y
Vendor
Intel
Product
Xeon Gold 5420\+
Intel
Xeon Gold 5420\+
Vendor
Intel
Product
Xeon Gold 5423n
Intel
Xeon Gold 5423n
Vendor
Intel
Product
Xeon Gold 5433n
Intel
Xeon Gold 5433n
Vendor
Intel
Product
Xeon Gold 6403n
Intel
Xeon Gold 6403n
Vendor
Intel
Product
Xeon Gold 6414u
Intel
Xeon Gold 6414u
Vendor
Intel
Product
Xeon Gold 6416h
Intel
Xeon Gold 6416h
Vendor
Intel
Product
Xeon Gold 6418h
Intel
Xeon Gold 6418h
Vendor
Intel
Product
Xeon Gold 6421n
Intel
Xeon Gold 6421n
Vendor
Intel
Product
Xeon Gold 6423n
Intel
Xeon Gold 6423n
Vendor
Intel
Product
Xeon Gold 6426y
Intel
Xeon Gold 6426y
Vendor
Intel
Product
Xeon Gold 6428n
Intel
Xeon Gold 6428n
Vendor
Intel
Product
Xeon Gold 6430
Intel
Xeon Gold 6430
Vendor
Intel
Product
Xeon Gold 6433n
Intel
Xeon Gold 6433n
Vendor
Intel
Product
Xeon Gold 6433ne
Intel
Xeon Gold 6433ne
Vendor
Intel
Product
Xeon Gold 6434
Intel
Xeon Gold 6434
Vendor
Intel
Product
Xeon Gold 6434h
Intel
Xeon Gold 6434h
Vendor
Intel
Product
Xeon Gold 6438m
Intel
Xeon Gold 6438m
Vendor
Intel
Product
Xeon Gold 6438n
Intel
Xeon Gold 6438n
Vendor
Intel
Product
Xeon Gold 6438y\+
Intel
Xeon Gold 6438y\+
Vendor
Intel
Product
Xeon Gold 6442y
Intel
Xeon Gold 6442y
Vendor
Intel
Product
Xeon Gold 6443n
Intel
Xeon Gold 6443n
Vendor
Intel
Product
Xeon Gold 6444y
Intel
Xeon Gold 6444y
Vendor
Intel
Product
Xeon Gold 6448h
Intel
Xeon Gold 6448h
Vendor
Intel
Product
Xeon Gold 6448y
Intel
Xeon Gold 6448y
Vendor
Intel
Product
Xeon Gold 6454s
Intel
Xeon Gold 6454s
Vendor
Intel
Product
Xeon Gold 6458q
Intel
Xeon Gold 6458q
Vendor
Intel
Product
Xeon Platinum 8444h
Intel
Xeon Platinum 8444h
Vendor
Intel
Product
Xeon Platinum 8450h
Intel
Xeon Platinum 8450h
Vendor
Intel
Product
Xeon Platinum 8452y
Intel
Xeon Platinum 8452y
Vendor
Intel
Product
Xeon Platinum 8454h
Intel
Xeon Platinum 8454h
Vendor
Intel
Product
Xeon Platinum 8458p
Intel
Xeon Platinum 8458p
Vendor
Intel
Product
Xeon Platinum 8460h
Intel
Xeon Platinum 8460h
Vendor
Intel
Product
Xeon Platinum 8460y\+
Intel
Xeon Platinum 8460y\+
Vendor
Intel
Product
Xeon Platinum 8461v
Intel
Xeon Platinum 8461v
Vendor
Intel
Product
Xeon Platinum 8462y\+
Intel
Xeon Platinum 8462y\+
Vendor
Intel
Product
Xeon Platinum 8468
Intel
Xeon Platinum 8468
Vendor
Intel
Product
Xeon Platinum 8468h
Intel
Xeon Platinum 8468h
Vendor
Intel
Product
Xeon Platinum 8468v
Intel
Xeon Platinum 8468v
Vendor
Intel
Product
Xeon Platinum 8470
Intel
Xeon Platinum 8470
Vendor
Intel
Product
Xeon Platinum 8470n
Intel
Xeon Platinum 8470n
Vendor
Intel
Product
Xeon Platinum 8471n
Intel
Xeon Platinum 8471n
Vendor
Intel
Product
Xeon Platinum 8480\+
Intel
Xeon Platinum 8480\+
Vendor
Intel
Product
Xeon Platinum 8490h
Intel
Xeon Platinum 8490h
Vendor
Intel
Product
Xeon Silver 4410t
Intel
Xeon Silver 4410t
Vendor
Intel
Product
Xeon Silver 4410y
Intel
Xeon Silver 4410y
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
