PT-2023-5856 · Supermicro · Supermicro X11Sae-F+1

CVE-2023-40288

·

Published

2023-08-17

·

Updated

2025-06-18

CVSS v3.1

8.3

High

VectorAV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Supermicro X11SSM-F version 1.66 Supermicro X11SAE-F version 1.66 Supermicro X11SSE-F version 1.66
Description An issue exists in the web interface of Supermicro X11 series BMC IPMI servers due to inadequate protection of the web page structure. This allows a remote attacker to conduct a cross-site scripting (XSS) attack using a specially crafted GET request. The issue could be exploited by an attacker to potentially gain unauthorized access or control.
Recommendations For Supermicro X11SSM-F version 1.66, consider disabling the web interface until a patch is available. For Supermicro X11SAE-F version 1.66, restrict access to the BMC IPMI server to minimize the risk of exploitation. For Supermicro X11SSE-F version 1.66, avoid using the web interface for sensitive operations until the issue is resolved. As a temporary workaround, consider implementing additional security measures, such as input validation and sanitization, to prevent XSS attacks.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-06543
CVE-2023-40288

Affected Products

Supermicro X11Sae-F
Supermicro X11Sse-F