PT-2019-14739 · Supermicro · Supermicro X10+1

Publicado

2019-09-21

·

Atualizado

2020-08-24

·

CVE-2019-16650

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Supermicro X10 and X11 products (affected versions not specified)
Description The issue allows a client's access privileges to be transferred to a different client that later has the same socket file descriptor number. An attacker can exploit this by connecting to the virtual media service and then connecting virtual USB devices to the server managed by the BMC.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2019-16650

Produtos afetados

Supermicro X10
Supermicro X11