A command injection issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker can exploit this to elevate privileges from a user with BMC administrative privileges.
References
Configurations
No configuration.
History
21 Nov 2024, 08:19
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.supermicro.com/en/support/security_BMC_IPMI_Oct_2023 - | |
References | () https://www.supermicro.com/en/support/security_center#%21advisories - |
06 Aug 2024, 15:35
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.2 |
CWE | CWE-269 |
27 Mar 2024, 04:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-03-27 04:15
Updated : 2024-11-21 08:19
NVD link : CVE-2023-40289
Mitre link : CVE-2023-40289
CVE.ORG link : CVE-2023-40289
JSON object : View
Products Affected
No product.
CWE
CWE-269
Improper Privilege Management