PT-2020-7452 · Supermicro · Supermicro X9+1

Published

2020-01-02

·

Updated

2020-01-14

·

CVE-2013-3620

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Supermicro X9 generation motherboards versions prior to 3.15 (SMT X9 315) Supermicro X8 generation motherboards versions prior to SMT X8 312
Description: The issue concerns hardcoded WSMan credentials in the Intelligent Platform Management Interface (IPMI) with firmware for certain Supermicro motherboards. This could potentially allow unauthorized access.
Recommendations: For Supermicro X9 generation motherboards versions prior to 3.15 (SMT X9 315), update the firmware to version 3.15 (SMT X9 315) or later. For Supermicro X8 generation motherboards versions prior to SMT X8 312, update the firmware to SMT X8 312 or later.

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-3620

Affected Products

Supermicro X8
Supermicro X9