CVE-2023-31189

MEDIUM
Published Feb 14, 2024 Modified Jan 14, 2026 CWE-287

Description

Improper authentication in some Intel(R) Server Product OpenBMC firmware before version egs-1.09 may allow an authenticated user to enable escalation of privilege via local access.

Is your site exposed to CVE-2023-31189?

Run a free security scan — no signup, results in seconds.

CVSS v3.1 Score

5.2
MEDIUM
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

Weakness Type (CWE)

CWE-287 Improper Authentication

Affected Products

Vendor Product
intel openbmc
intel xeon_bronze_3408u
intel xeon_gold_5403n
intel xeon_gold_5411n
intel xeon_gold_5412u
intel xeon_gold_5415\+
intel xeon_gold_5416s
intel xeon_gold_5418n
intel xeon_gold_5418y
intel xeon_gold_5420\+
intel xeon_gold_5423n
intel xeon_gold_5433n
intel xeon_gold_6403n
intel xeon_gold_6414u
intel xeon_gold_6416h
intel xeon_gold_6418h
intel xeon_gold_6421n
intel xeon_gold_6423n
intel xeon_gold_6426y
intel xeon_gold_6428n
intel xeon_gold_6430
intel xeon_gold_6433n
intel xeon_gold_6433ne
intel xeon_gold_6434
intel xeon_gold_6434h
intel xeon_gold_6438m
intel xeon_gold_6438n
intel xeon_gold_6438y\+
intel xeon_gold_6442y
intel xeon_gold_6443n
intel xeon_gold_6444y
intel xeon_gold_6448h
intel xeon_gold_6448y
intel xeon_gold_6454s
intel xeon_gold_6458q
intel xeon_platinum_8444h
intel xeon_platinum_8450h
intel xeon_platinum_8452y
intel xeon_platinum_8454h
intel xeon_platinum_8458p
intel xeon_platinum_8460h
intel xeon_platinum_8460y\+
intel xeon_platinum_8461v
intel xeon_platinum_8462y\+
intel xeon_platinum_8468
intel xeon_platinum_8468h
intel xeon_platinum_8468v
intel xeon_platinum_8470
intel xeon_platinum_8470n
intel xeon_platinum_8471n
intel xeon_platinum_8480\+
intel xeon_platinum_8490h
intel xeon_silver_4410t
intel xeon_silver_4410y

References

Frequently Asked Questions

What is CVE-2023-31189? +
Improper authentication in some Intel(R) Server Product OpenBMC firmware before version egs-1.09 may allow an authenticated user to enable escalation of privilege via local access. It has a CVSS v3.1 base score of 5.2 (MEDIUM).
How severe is CVE-2023-31189? +
CVE-2023-31189 has a CVSS v3.1 score of 5.2 out of 10, rated MEDIUM. This is a medium-severity vulnerability that should be remediated as part of regular maintenance.
What products are affected by CVE-2023-31189? +
CVE-2023-31189 affects products from intel, specifically: openbmc, xeon_bronze_3408u, xeon_gold_5403n, xeon_gold_5411n, xeon_gold_5412u, xeon_gold_5415\+, xeon_gold_5416s, xeon_gold_5418n, xeon_gold_5418y, xeon_gold_5420\+, xeon_gold_5423n, xeon_gold_5433n, xeon_gold_6403n, xeon_gold_6414u, xeon_gold_6416h, xeon_gold_6418h, xeon_gold_6421n, xeon_gold_6423n, xeon_gold_6426y, xeon_gold_6428n, xeon_gold_6430, xeon_gold_6433n, xeon_gold_6433ne, xeon_gold_6434, xeon_gold_6434h, xeon_gold_6438m, xeon_gold_6438n, xeon_gold_6438y\+, xeon_gold_6442y, xeon_gold_6443n, xeon_gold_6444y, xeon_gold_6448h, xeon_gold_6448y, xeon_gold_6454s, xeon_gold_6458q, xeon_platinum_8444h, xeon_platinum_8450h, xeon_platinum_8452y, xeon_platinum_8454h, xeon_platinum_8458p, xeon_platinum_8460h, xeon_platinum_8460y\+, xeon_platinum_8461v, xeon_platinum_8462y\+, xeon_platinum_8468, xeon_platinum_8468h, xeon_platinum_8468v, xeon_platinum_8470, xeon_platinum_8470n, xeon_platinum_8471n, xeon_platinum_8480\+, xeon_platinum_8490h, xeon_silver_4410t, xeon_silver_4410y. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2023-31189? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2023-31189 — free, no signup required.