PT-2023-5859 · Supermicro · Supermicro X11Sae-F+2

CVE-2023-40289

·

Publicado

2023-08-17

·

Atualizado

2025-06-18

CVSS v2.0

8.3

Alta

VetorAV:N/AC:L/Au:M/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Supermicro X11SSM-F, X11SAE-F, and X11SSE-F versions 1.66 Supermicro BMC versions 8.3 through 9.6
Description A command injection issue was discovered, allowing an attacker to elevate privileges from a user with BMC administrative privileges. This issue is related to insufficient checking of arguments passed to a command. An attacker can exploit this to execute arbitrary commands. The issue affects Supermicro BMC servers, specifically the X11 series, and has a critical rating.
Recommendations For Supermicro X11SSM-F, X11SAE-F, and X11SSE-F version 1.66, consider disabling administrative privileges for BMC users until a patch is available. For Supermicro BMC versions 8.3 through 9.6, restrict access to the BMC interface to minimize the risk of exploitation. As a temporary workaround, consider disabling the command injection functionality until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Command Injection

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-06546
CVE-2023-40289

Produtos afetados

Supermicro Bmc
Supermicro X11Sae-F
Supermicro X11Sse-F