SB2019012406 - Privilege escalation in OpenBMC



SB2019012406 - Privilege escalation in OpenBMC

Published: January 24, 2019

Security Bulletin ID SB2019012406
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Adjecent network
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Privilege escalation (CVE-ID: CVE-2019-6260)

The vulnerability allows an adjacent unauthenticated attacker to gain elevated privileges on the system.

The vulnerability exists in ASPEED ast2400 and ast2500 Baseband Management Controller (BMC) hardware due to an error in implementation of Advanced High-performance Bus (AHB) bridges on the LPC and PCIe buses. An adjacent attacker can gain read and write access to the BMC’s physical address space from the host and control of the BMC.

Note: the vulnerability has been nicknamed "pantsdown".


Remediation

Install update from vendor's website.