PT-2023-25034 · Supermicro · Supermicro Motherboard X12Dpg-Qr

Published

2023-08-17

·

Updated

2023-08-29

·

CVE-2023-34853

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Supermicro motherboard X12DPG-QR version 1.4b
Description The issue allows local attackers to hijack control flow via manipulation of the SmcSecurityEraseSetupVar variable, potentially enabling them to gain unauthorized access or control.
Recommendations For Supermicro motherboard X12DPG-QR version 1.4b, as a temporary workaround, consider restricting access to the SmcSecurityEraseSetupVar variable until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2023-34853

Affected Products

Supermicro Motherboard X12Dpg-Qr