PT-2023-2915 · Supermicro · Supermicro X11Sse-F
Published
2023-01-15
·
Updated
2023-05-16
·
CVE-2022-43309
CVSS v2.0
6.2
Medium
| Vector | AV:L/AC:L/Au:S/C:N/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Supermicro X11SSL-CF HW Rev 1.01, BMC firmware version 1.63
Description
The issue is related to the PMBus interface of the VRM module in Supermicro BMC controllers, where there is an incorrect assignment of permissions for a critical resource. Exploitation of this issue can allow an attacker to physically disable the CPU without the possibility of subsequent recovery. Researchers from the University of Birmingham discovered this vulnerability, which has been named PMFault, and it can be used to damage servers without physical access but with privileged access to the operating system.
Recommendations
For Supermicro X11SSL-CF HW Rev 1.01, BMC firmware version 1.63, update the firmware to a version that contains the fix for this issue.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Supermicro X11Sse-F