PT-2018-12185 · Supermicro · Supermicro C7+8
Published
2018-07-09
·
Updated
2019-10-03
·
CVE-2018-13787
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Supermicro X11S, X10, X9, X8SI, K1SP, C9X299, C7, B1, A2, and A1 products (affected versions not specified)
Description
The issue is related to a misconfigured Descriptor Region in certain Supermicro products, which allows operating system programs to modify firmware.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Supermicro A1
Supermicro A2
Supermicro C7
Supermicro C9X299
Supermicro K1Sp
Supermicro X10
Supermicro X11
Supermicro X8
Supermicro X9