PT-2023-5856 · Supermicro · Supermicro X11Sae-F+1
Published
2023-08-17
·
Updated
2025-06-18
·
CVE-2023-40288
CVSS v3.1
8.3
High
| Vector | AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Supermicro X11SSM-F version 1.66
Supermicro X11SAE-F version 1.66
Supermicro X11SSE-F version 1.66
Description
An issue exists in the web interface of Supermicro X11 series BMC IPMI servers due to inadequate protection of the web page structure. This allows a remote attacker to conduct a cross-site scripting (XSS) attack using a specially crafted GET request. The issue could be exploited by an attacker to potentially gain unauthorized access or control.
Recommendations
For Supermicro X11SSM-F version 1.66, consider disabling the web interface until a patch is available.
For Supermicro X11SAE-F version 1.66, restrict access to the BMC IPMI server to minimize the risk of exploitation.
For Supermicro X11SSE-F version 1.66, avoid using the web interface for sensitive operations until the issue is resolved.
As a temporary workaround, consider implementing additional security measures, such as input validation and sanitization, to prevent XSS attacks.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Supermicro X11Sae-F
Supermicro X11Sse-F