CVE Vulnerabilities

CVE-2023-33412

Published: Dec 07, 2023 | Modified: Dec 13, 2023
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The web interface in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions before 3.17.02, allows remote authenticated users to execute arbitrary commands via a crafted request targeting vulnerable cgi endpoints.

Affected Software

Name Vendor Start Version End Version
M11sdv-4c-ln4f_firmware Supermicro * 3.17.02 (including)

References