CVE-2019-6260
Summary
| CVE | CVE-2019-6260 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-01-22 20:29:00 UTC |
| Updated | 2020-08-24 17:37:00 UTC |
| Description | The ASPEED ast2400 and ast2500 Baseband Management Controller (BMC) hardware and firmware implement Advanced High-performance Bus (AHB) bridges, which allow arbitrary read and write access to the BMC's physical address space from the host (or from the network in unusual cases where the BMC console uart is attached to a serial concentrator). This CVE applies to the specific cases of iLPC2AHB bridge Pt I, iLPC2AHB bridge Pt II, PCIe VGA P2A bridge, DMA from/to arbitrary BMC memory via X-DMA, UART-based SoC Debug interface, LPC2AHB bridge, PCIe BMC P2A bridge, and Watchdog setup. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Aspeedtech | Ast2400 | - | All | All | All |
| Hardware | Aspeedtech | Ast2400 | - | All | All | All |
| Operating System | Aspeedtech | Ast2400 Firmware | All | All | All | All |
| Operating System | Aspeedtech | Ast2400 Firmware | All | All | All | All |
| Hardware | Aspeedtech | Ast2500 | - | All | All | All |
| Hardware | Aspeedtech | Ast2500 | - | All | All | All |
| Operating System | Aspeedtech | Ast2500 Firmware | All | All | All | All |
| Operating System | Aspeedtech | Ast2500 Firmware | All | All | All | All |
| Application | Netapp | Fas/aff Baseboard Management Controller | All | All | All | All |
| Application | Netapp | Fas/aff Baseboard Management Controller | All | All | All | All |
| Application | Netapp | Fas/aff Baseboard Management Controller | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Broadcom Inc. | Connecting Everything | CONFIRM | www.broadcom.com | Third Party Advisory |
| CVE-2019-6260 ASPEED BMC Vulnerability in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | Patch, Third Party Advisory |
| CVE-2019-6260: Gaining control of BMC from the host processor | Ramblings | MISC | www.flamingspork.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.