PT-2024-5267 · Supermicro · Supermicro X11Dph-Tq+2

Eason

+1

·

Published

2024-07-15

·

Updated

2024-08-01

·

CVE-2024-36434

CVSS v3.1

7.5

High

VectorAV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Supermicro X11DPH-T versions prior to BIOS firmware 4.4 Supermicro X11DPH-Tq versions prior to BIOS firmware 4.4 Supermicro X11DPH-i versions prior to BIOS firmware 4.4
Description A vulnerability was discovered in the SMM callout component of Supermicro BMC controller firmware, related to a buffer overflow in memory. Exploitation of this issue may allow an attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations For Supermicro X11DPH-T with BIOS firmware before 4.4, update the BIOS firmware to version 4.4 or later. For Supermicro X11DPH-Tq with BIOS firmware before 4.4, update the BIOS firmware to version 4.4 or later. For Supermicro X11DPH-i with BIOS firmware before 4.4, update the BIOS firmware to version 4.4 or later.

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2024-05886
CVE-2024-36434

Affected Products

Supermicro Bmc
Supermicro X11Dph-Tq
Supermicro X11Dph-I