ZeroHour

Vulnerabilities

22 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-40284
An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices.

An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue.

NVD description · AI analysis pending
8.3
group max
<1%
  • supermicro x11ssm-f firmware
  • supermicro x11sae-f firmware
  • supermicro x11sse-f firmware
CVE-2023-33412
+2 in the same advisory: …33413 …33411
The web interface in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based d

The web interface in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions before 3.17.02, allows remote authenticated users to execute arbitrary commands via a crafted request targeting vulnerable cgi endpoints.

NVD description · AI analysis pending
8.8
group max
1%
  • supermicro m11sdv-4c-ln4f firmware
  • supermicro m11sdv-4ct-ln4f firmware
  • supermicro m11sdv-8c-ln4f firmware
  • +1 more
CVE-2023-34853
Buffer Overflow vulnerability in Supermicro motherboard X12DPG-QR 1.4b allows local attackers to hijack control flow via manipulation of SmcSecurityEraseSetupVa

Buffer Overflow vulnerability in Supermicro motherboard X12DPG-QR 1.4b allows local attackers to hijack control flow via manipulation of SmcSecurityEraseSetupVar variable.

NVD description · AI analysis pending
7.8<1%
  • supermicro x12dai-n6 firmware
  • supermicro x12ddw-a6 firmware
  • supermicro x12dgo-6 firmware
  • +1 more
CVE-2021-25857
+1 in the same advisory: …25856
An issue was discovered in pcmt superMicro-CMS version 3.11, allows authenticated attackers to execute arbitrary code via the font_type parameter to setup.php.

An issue was discovered in pcmt superMicro-CMS version 3.11, allows authenticated attackers to execute arbitrary code via the font_type parameter to setup.php.

NVD description · AI analysis pending
7.2
group max
<1% PoC
  • supermicro-cms project supermicro-cms
CVE-2023-35861
A shell-injection vulnerability in email notifications on Supermicro motherboards (such as H12DST-B before 03.10.35) allows remote attackers to inject execute a

A shell-injection vulnerability in email notifications on Supermicro motherboards (such as H12DST-B before 03.10.35) allows remote attackers to inject execute arbitrary commands as root on the BMC.

NVD description · AI analysis pending
9.82% PoC
  • supermicro h12dst-b firmware
  • supermicro x13dai-t firmware
  • supermicro x13ddw-a firmware
  • +1 more
CVE-2022-43309
Supermicro X11SSL-CF HW Rev 1.01, BMC firmware v1.63 was discovered to contain insecure permissions.

Supermicro X11SSL-CF HW Rev 1.01, BMC firmware v1.63 was discovered to contain insecure permissions.

NVD description · AI analysis pending
5.5<1%
  • supermicro x11ssl-cf firmware
  • supermicro x11dac firmware
  • supermicro x11dai-n firmware
  • +1 more
CVE-2021-22887
A vulnerability in the BIOS of Pulse Secure (PSA-Series Hardware) models PSA5000 and PSA7000 could allow an attacker to compromise BIOS firmware.

A vulnerability in the BIOS of Pulse Secure (PSA-Series Hardware) models PSA5000 and PSA7000 could allow an attacker to compromise BIOS firmware. This vulnerability can be exploited only as part of an attack chain. Before an attacker can compromise the BIOS, they must exploit the device.

NVD description · AI analysis pending
2.3<1%
  • pulsesecure psa-5000 firmware
  • pulsesecure psa-7000 firmware
  • pulsesecure x10slh-f firmware
  • +1 more
CVE-2020-15046
The web interface on Supermicro X10DRH-iT motherboards with BIOS 2.0a and IPMI firmware 03.40 allows remote attackers to exploit a cgi/config_user.cgi CSRF issu

The web interface on Supermicro X10DRH-iT motherboards with BIOS 2.0a and IPMI firmware 03.40 allows remote attackers to exploit a cgi/config_user.cgi CSRF issue to add new admin users. The fixed versions are BIOS 3.2 and firmware 03.88.

NVD description · AI analysis pending
8.82% PoC ×2
  • supermicro x10drh-it bios
  • supermicro x10drh-it firmware
CVE-2019-19642
On SuperMicro X8STi-F motherboards with IPMI firmware 2.06 and BIOS 02.68, the Virtual Media feature allows OS Command Injection by authenticated attackers who

On SuperMicro X8STi-F motherboards with IPMI firmware 2.06 and BIOS 02.68, the Virtual Media feature allows OS Command Injection by authenticated attackers who can send HTTP requests to the IPMI IP address. This requires a POST to /rpc/setvmdrive.asp with shell metacharacters in ShareHost or ShareName. The attacker can achieve a persistent backdoor.

NVD description · AI analysis pending
8.819% PoC
  • supermicro x8sti-f bios
  • supermicro x8sti-f firmware
CVE-2019-16650
+1 in the same advisory: …16649
On Supermicro X10 and X11 products, a client's access privileges may be transferred to a different client that later has the same socket file descriptor number.

On Supermicro X10 and X11 products, a client's access privileges may be transferred to a different client that later has the same socket file descriptor number. In opportunistic circumstances, an attacker can simply connect to the virtual media service, and then connect virtual USB devices to the server managed by the BMC.

NVD description · AI analysis pending
10.02%
  • supermicro x11dai-n firmware
  • supermicro x11dac firmware
  • supermicro x11dph-tq firmware
  • +1 more
CVE-2019-13131
Super Micro SuperDoctor 5, when restrictions are not implemented in agent.cfg, allows remote attackers to execute arbitrary commands via NRPE.

Super Micro SuperDoctor 5, when restrictions are not implemented in agent.cfg, allows remote attackers to execute arbitrary commands via NRPE.

NVD description · AI analysis pending
9.84% PoC
  • supermicro superdoctor 5
CVE-2018-13787
Certain Supermicro X11S, X10, X9, X8SI, K1SP, C9X299, C7, B1, A2, and A1 products have a misconfigured Descriptor Region, allowing OS programs to modify firmwar

Certain Supermicro X11S, X10, X9, X8SI, K1SP, C9X299, C7, B1, A2, and A1 products have a misconfigured Descriptor Region, allowing OS programs to modify firmware.

NVD description · AI analysis pending
6.7<1%
  • supermicro x11ssz firmware
  • supermicro x11ssv firmware
  • supermicro x11ssql firmware
  • +1 more