An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue.
References
Link | Resource |
---|---|
https://www.supermicro.com/en/support/security_BMC_IPMI_Oct_2023 | Vendor Advisory |
https://www.supermicro.com/en/support/security_center#%21advisories | Vendor Advisory |
https://www.supermicro.com/en/support/security_BMC_IPMI_Oct_2023 | Vendor Advisory |
https://www.supermicro.com/en/support/security_center#%21advisories | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
History
18 Jun 2025, 18:50
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.supermicro.com/en/support/security_BMC_IPMI_Oct_2023 - Vendor Advisory | |
References | () https://www.supermicro.com/en/support/security_center#%21advisories - Vendor Advisory | |
First Time |
Supermicro x11sse-f
Supermicro Supermicro x11sae-f Supermicro x11sae-f Firmware Supermicro x11ssm-f Firmware Supermicro x11ssm-f Supermicro x11sse-f Firmware |
|
CPE | cpe:2.3:h:supermicro:x11sae-f:-:*:*:*:*:*:*:* cpe:2.3:o:supermicro:x11sae-f_firmware:1.66:*:*:*:*:*:*:* cpe:2.3:o:supermicro:x11sse-f_firmware:1.66:*:*:*:*:*:*:* cpe:2.3:h:supermicro:x11ssm-f:-:*:*:*:*:*:*:* cpe:2.3:o:supermicro:x11ssm-f_firmware:1.66:*:*:*:*:*:*:* cpe:2.3:h:supermicro:x11sse-f:-:*:*:*:*:*:*:* |
21 Nov 2024, 08:19
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.supermicro.com/en/support/security_BMC_IPMI_Oct_2023 - | |
References | () https://www.supermicro.com/en/support/security_center#%21advisories - |
05 Aug 2024, 15:35
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-79 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.3 |
27 Mar 2024, 04:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-03-27 04:15
Updated : 2025-06-18 18:50
NVD link : CVE-2023-40288
Mitre link : CVE-2023-40288
CVE.ORG link : CVE-2023-40288
JSON object : View
Products Affected
supermicro
- x11sae-f_firmware
- x11sse-f_firmware
- x11sse-f
- x11ssm-f
- x11sae-f
- x11ssm-f_firmware
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')