ZeroHour

CVE-2023-33411

CVSS 3.1
7.5 high
EPSS
1%p68
Published
()
Modified
Description

A web server in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions up to 3.17.02, allows remote unauthenticated users to perform directory traversal, potentially disclosing sensitive information.

Vendors
supermicro
Products
m11sdv-4c-ln4f firmware, m11sdv-4ct-ln4f firmware, m11sdv-8c-ln4f firmware, m11sdv-8ct-ln4f firmware, m11sdv-8c\+-ln4f firmware, c9x299-pg firmware, c9x299-pg300 firmware, c9x299-pg300f firmware, c9x299-pgf firmware, c9x299-pgf-l firmware, c9x299-rpgf firmware, c9x299-rpgf-l firmware
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.