SB2019012406 - Privilege escalation in OpenBMC
Published: January 24, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Privilege escalation (CVE-ID: CVE-2019-6260)
The vulnerability allows an adjacent unauthenticated attacker to gain elevated privileges on the system.
The vulnerability exists in ASPEED ast2400 and ast2500 Baseband Management Controller (BMC) hardware due to an error in implementation of Advanced High-performance Bus (AHB) bridges on the LPC and PCIe buses. An adjacent attacker can gain read and write access to the BMC’s physical address space from the host and control of the BMC.
Note: the vulnerability has been nicknamed "pantsdown".
Remediation
Install update from vendor's website.