PT-2020-7452 · Supermicro · Supermicro X9+1
Published
2020-01-02
·
Updated
2020-01-14
·
CVE-2013-3620
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Supermicro X9 generation motherboards versions prior to 3.15 (SMT X9 315)
Supermicro X8 generation motherboards versions prior to SMT X8 312
Description:
The issue concerns hardcoded WSMan credentials in the Intelligent Platform Management Interface (IPMI) with firmware for certain Supermicro motherboards. This could potentially allow unauthorized access.
Recommendations:
For Supermicro X9 generation motherboards versions prior to 3.15 (SMT X9 315), update the firmware to version 3.15 (SMT X9 315) or later.
For Supermicro X8 generation motherboards versions prior to SMT X8 312, update the firmware to SMT X8 312 or later.
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Supermicro X8
Supermicro X9