CVE-2023-30768
Last modified
CVE-2023-30768 is a medium-severity vulnerability rated 6.7/10 on the CVSS scale. Improper access control in the Intel(R) Server Board S2600WTT belonging to the Intel(R) Server Board S2600WT Family with the BIOS version 0016 may allow a privileged user to potentially enable escalation of privilege via local access.. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
Improper access control in the Intel(R) Server Board S2600WTT belonging to the Intel(R) Server Board S2600WT Family with the BIOS version 0016 may allow a privileged user to potentially enable escalation of privilege via local access.
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Intel | Server Board S1200v3rpl Firmware | < 0006 |
| Intel | Server Board S1200v3rpm Firmware | < 0006 |
| Intel | Server Board S1200v3rpo Firmware | < 0006 |
| Intel | Server Board S1200v3rps Firmware | < 0006 |
| Intel | Server Board S1400fp2 Firmware | < 0005 |
| Intel | Server Board S1400fp4 Firmware | < 0005 |
| Intel | Server Board S1400sp4 Firmware | < 0005 |
| Intel | Server Board S1400sp2 Firmware | < 0005 |
| Intel | Server Board S1600jp2 Firmware | < 0005 |
| Intel | Server Board S1600jp4 Firmware | < 0005 |
| Intel | Server Board S2400bb4 Firmware | < 0005 |
| Intel | Server Board S2400ep2 Firmware | < 0005 |
| Intel | Server Board S2400ep4 Firmware | < 0005 |
| Intel | Server Board S2400sc2 Firmware | < 0005 |
| Intel | Server Board S2600co4 Firmware | < 0005 |
| Intel | Server Board S2600coe Firmware | < 0005 |
| Intel | Server Board S2600coeioc Firmware | < 0005 |
| Intel | Server Board S2600cp2 Firmware | < 0005 |
| Intel | Server Board S2600cp2ioc Firmware | < 0005 |
| Intel | Server Board S2600cp2j Firmware | < 0005 |
| Intel | Server Board S2600cp4 Firmware | < 0005 |
| Intel | Server Board S2600cp4ioc Firmware | < 0005 |
| Intel | Server Board S2600gl Firmware | < 0005 |
| Intel | Server Board S2600gz Firmware | < 0005 |
| Intel | Server Board S2600ip4 Firmware | < 0005 |
| Intel | Server Board S2600ip4l Firmware | < 0005 |
| Intel | Workstation Board W2600cr2 Firmware | < 0005 |
| Intel | Workstation Board W2600cr2l Firmware | < 0005 |
| Intel | Server Board S2600jf Firmware | < 0005 |
| Intel | Server Board S2600wp Firmware | < 0005 |
| Intel | Server Board S4600lh2 Firmware | < 0005 |
| Intel | Server Board S4600lt2 Firmware | < 0005 |
| Intel | Server Board S2600wpf Firmware | < 0005 |
| Intel | Server Board S2600wpq Firmware | < 0005 |
| Intel | Server Board S2600jff Firmware | < 0005 |
| Intel | Server Board S2600jfq Firmware | < 0005 |
| Intel | Server Board S2600cw2r Firmware | < 0018 |
| Intel | Server Board S2600cw2sr Firmware | < 0018 |
| Intel | Server Board S2600cwtr Firmware | < 0018 |
| Intel | Server Board S2600cwtsr Firmware | < 0018 |
| Intel | Server Board S2600cw2s Firmware | < 0018 |
| Intel | Server Board S2600cwt Firmware | < 0018 |
| Intel | Server Board S2600cwts Firmware | < 0018 |
| Intel | Server Board S2600cw2 Firmware | < 0018 |
| Intel | Server Board S2600kpfr Firmware | < 0018 |
| Intel | Server Board S2600kpr Firmware | < 0018 |
| Intel | Server Board S2600kptr Firmware | < 0018 |
| Intel | Server Board S2600kp Firmware | < 0018 |
| Intel | Server Board S2600kpf Firmware | < 0018 |
| Intel | Server Board S2600tpnr Firmware | < 0018 |
Showing 50 of 64 affected configurations. See NVD for the full list.
References
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00056.htmlMitigation, Vendor Advisory
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00056.htmlMitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-30768?
How severe is CVE-2023-30768?
How do I fix CVE-2023-30768?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-30762Improper authentication vulnerability exists in KB-AHR serie…9.8
- CVE-2023-30763Heap-based overflow in Intel(R) SoC Watch based software bef…6.7
- CVE-2023-30764OS command injection vulnerability exists in KB-AHR series a…9.8
- CVE-2023-30765Delta Electronics InfraSuite Device Master versions prior t…9.8
- CVE-2023-30766Hidden functionality issue exists in KB-AHR series and KB-IR…9.8
- CVE-2023-30767Improper buffer restrictions in Intel(R) Optimization for Te…6.7
- CVE-2023-30769Vulnerability discovered is related to the peer-to-peer (p2p…9.8
- CVE-2023-3077The MStore API WordPress plugin before 3.9.8 does not saniti…9.8
- CVE-2023-30770A stack-based buffer overflow vulnerability was found in the…9.8
- CVE-2023-30771Incorrect Authorization vulnerability in Apache Software Fou…9.8
- CVE-2023-30772The Linux kernel before 6.2.9 has a race condition and resul…6.4
- CVE-2023-30774A vulnerability was found in the libtiff library. This flaw …5.5
Are you affected by CVE-2023-30768?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
