Home

Description

Improper input validation in the BackupBiosUpdate UEFI firmware SmiVariable driver for the Intel(R) Server D50DNP and M50FCP boards before version R01.02.0003 may allow a privileged user to potentially enable information disclosure via local access.

PUBLISHED Reserved 2024-10-10 | Published 2025-05-13 | Updated 2025-05-14 | Assigner intel




MEDIUM: 5.6CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
MEDIUM: 5.3CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N

Problem types

Information Disclosure

Improper Input Validation

References

intel.com/...en/security-center/advisory/intel-sa-01269.html

cve.org (CVE-2025-20034)

nvd.nist.gov (CVE-2025-20034)

Download JSON