CVE-2022-29494

Summary

CVECVE-2022-29494
StatePUBLIC
Assigner[email protected]
Source PriorityCVE Program / NVD first with legacy fallback
Published2023-02-16 21:15:00 UTC
Updated2023-08-08 14:21:00 UTC
DescriptionImproper input validation in firmware for OpenBMC in some Intel(R) platforms before versions egs-0.91-179 and bhs-04-45 may allow an authenticated user to potentially enable denial of service via network access.

Risk And Classification

Problem Types: CWE-20

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Hardware Intel C621a - All All All
Hardware Intel C627a - All All All
Hardware Intel C629a - All All All
Hardware Intel C741 - All All All
Operating System Intel Openbmc All All All All
Hardware Intel Xeon Gold 5315y - All All All
Hardware Intel Xeon Gold 5317 - All All All
Hardware Intel Xeon Gold 5318h - All All All
Hardware Intel Xeon Gold 5318n - All All All
Hardware Intel Xeon Gold 5318s - All All All
Hardware Intel Xeon Gold 5318y - All All All
Hardware Intel Xeon Gold 5320 - All All All
Hardware Intel Xeon Gold 5320h - All All All
Hardware Intel Xeon Gold 5320t - All All All
Hardware Intel Xeon Gold 6312u - All All All
Hardware Intel Xeon Gold 6314u - All All All
Hardware Intel Xeon Gold 6326 - All All All
Hardware Intel Xeon Gold 6328h - All All All
Hardware Intel Xeon Gold 6328hl - All All All
Hardware Intel Xeon Gold 6330 - All All All
Hardware Intel Xeon Gold 6330h - All All All
Hardware Intel Xeon Gold 6330n - All All All
Hardware Intel Xeon Gold 6334 - All All All
Hardware Intel Xeon Gold 6336y - All All All
Hardware Intel Xeon Gold 6338 - All All All
Hardware Intel Xeon Gold 6338n - All All All
Hardware Intel Xeon Gold 6338t - All All All
Hardware Intel Xeon Gold 6342 - All All All
Hardware Intel Xeon Gold 6346 - All All All
Hardware Intel Xeon Gold 6348 - All All All
Hardware Intel Xeon Gold 6348h - All All All
Hardware Intel Xeon Gold 6354 - All All All
Hardware Intel Xeon Platinum 8351n - All All All
Hardware Intel Xeon Platinum 8352m - All All All
Hardware Intel Xeon Platinum 8352s - All All All
Hardware Intel Xeon Platinum 8352v - All All All
Hardware Intel Xeon Platinum 8352y - All All All
Hardware Intel Xeon Platinum 8353h - All All All
Hardware Intel Xeon Platinum 8354h - All All All
Hardware Intel Xeon Platinum 8356h - All All All
Hardware Intel Xeon Platinum 8358 - All All All
Hardware Intel Xeon Platinum 8358p - All All All
Hardware Intel Xeon Platinum 8360h - All All All
Hardware Intel Xeon Platinum 8360hl - All All All
Hardware Intel Xeon Platinum 8360y - All All All
Hardware Intel Xeon Platinum 8362 - All All All
Hardware Intel Xeon Platinum 8368 - All All All
Hardware Intel Xeon Platinum 8368q - All All All
Hardware Intel Xeon Platinum 8376h - All All All
Hardware Intel Xeon Platinum 8376hl - All All All
Hardware Intel Xeon Platinum 8380 - All All All
Hardware Intel Xeon Platinum 8380h - All All All
Hardware Intel Xeon Platinum 8380hl - All All All
Hardware Intel Xeon Silver 4309y - All All All
Hardware Intel Xeon Silver 4310 - All All All
Hardware Intel Xeon Silver 4310t - All All All
Hardware Intel Xeon Silver 4314 - All All All
Hardware Intel Xeon Silver 4316 - All All All

References

ReferenceSourceLinkTags
INTEL-SA-00737 MISC www.intel.com
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

CVE.report and Source URL Uptime Status status.cve.report