CVE-2023-33411
—CVSS 3.1
7.5 high
EPSS
1%p68
Published
()
Modified
Description
A web server in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions up to 3.17.02, allows remote unauthenticated users to perform directory traversal, potentially disclosing sensitive information.
- Vendors
- supermicro
- Products
- m11sdv-4c-ln4f firmware, m11sdv-4ct-ln4f firmware, m11sdv-8c-ln4f firmware, m11sdv-8ct-ln4f firmware, m11sdv-8c\+-ln4f firmware, c9x299-pg firmware, c9x299-pg300 firmware, c9x299-pg300f firmware, c9x299-pgf firmware, c9x299-pgf-l firmware, c9x299-rpgf firmware, c9x299-rpgf-l firmware
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.