PT-2019-3128 · Supermicro · Supermicro Bmc
Published
2019-09-03
·
Updated
2019-09-03
CVSS v2.0
8.5
High
| Vector | AV:N/AC:M/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Supermicro BMC versions (affected versions not specified)
Description
The issue is caused by insufficient security restrictions for critical management functions in the virtual media service of Supermicro BMC controllers. This can be exploited by a remote attacker to gain full control over the device by intercepting the authentication packet of a legitimate user.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Supermicro Bmc