CVE-2013-3609 PUBLISHED CVSS 10 CRITICAL

The web interface in the Intelligent Platform Management Interface (IPMI) implementation on Supermicro H8DC*, H8DG*, H8SCM-F, H8SGL-F, H8SM*, X7SP*, X8DT*, X8SI*, X9DAX-*, X9DB*, X9DR*, X9QR*, X9SBAA-F, X9SC*, X9SPU-F, and X9SR* devices relies on JavaScript code on the client for authorization checks, which allows remote authenticated users to bypass intended access restrictions via a crafted request, related to the PrivilegeCallBack function.

EPSS 1.59% · 81.6th percentile

Risk Scores

CVSS v2.0
10
EPSS Score
1.59%
81.6th percentile

Affected Products

VendorProductVersions
supermicrox9sbaa-f
supermicrox8dtl-3f
supermicrox9scl\+-f
supermicrox8dtl-if
supermicrox9scl-f
supermicroh8dct-ibqf
supermicrox9drff-7
supermicrox9dax-if
supermicrox8dtu-6f\+-lr
supermicrox9drff
supermicrox9drg-hf
supermicrox9db3-f
supermicrox9dax-itf
supermicroh8sme-f
supermicrox8dtu-6tf\+-lr
supermicrox9sre-f
supermicrox9dbi-f
supermicrox9drt-h6ibff
supermicrox9drff-7tg\+
supermicrox8sie-f

…and 114 more

Timeline

References

Open in Interactive Console →