PT-2019-3128 · Supermicro · Supermicro Bmc

Published

2019-09-03

·

Updated

2019-09-03

CVSS v2.0

8.5

High

VectorAV:N/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Supermicro BMC versions (affected versions not specified)
Description The issue is caused by insufficient security restrictions for critical management functions in the virtual media service of Supermicro BMC controllers. This can be exploited by a remote attacker to gain full control over the device by intercepting the authentication packet of a legitimate user.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-03113

Affected Products

Supermicro Bmc