ZeroHour

CVE-2023-33412

CVSS 3.1
8.8 high
EPSS
1%p65
Published
()
Modified
Description

The web interface in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions before 3.17.02, allows remote authenticated users to execute arbitrary commands via a crafted request targeting vulnerable cgi endpoints.

Vendors
supermicro
Products
m11sdv-4c-ln4f firmware, m11sdv-4ct-ln4f firmware, m11sdv-8c-ln4f firmware, m11sdv-8ct-ln4f firmware, m11sdv-8c\+-ln4f firmware, c9x299-pg firmware, c9x299-pg300 firmware, c9x299-pg300f firmware, c9x299-pgf firmware, c9x299-pgf-l firmware, c9x299-rpgf firmware, c9x299-rpgf-l firmware
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.