PT-2018-12185 · Supermicro · Supermicro C7+8

Published

2018-07-09

·

Updated

2019-10-03

·

CVE-2018-13787

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Supermicro X11S, X10, X9, X8SI, K1SP, C9X299, C7, B1, A2, and A1 products (affected versions not specified)
Description The issue is related to a misconfigured Descriptor Region in certain Supermicro products, which allows operating system programs to modify firmware.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2018-13787

Affected Products

Supermicro A1
Supermicro A2
Supermicro C7
Supermicro C9X299
Supermicro K1Sp
Supermicro X10
Supermicro X11
Supermicro X8
Supermicro X9