CVE-2013-3607: Buffer Overflow
Multiple stack-based buffer overflows in the web interface in the Intelligent Platform Management Interface (IPMI) implementation on Supermicro H8DC, H8DG, H8SCM-F, H8SGL-F, H8SM, X7SP, X8DT, X8SI, X9DAX-, X9DB, X9DR, X9QR, X9SBAA-F, X9SC, X9SPU-F, and X9SR devices allow remote attackers to execute arbitrary code on the Baseboard Management Controller (BMC), as demonstrated by the (1) username or (2) password field in login.cgi.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-3607?
CVE-2013-3607 is classified as a critical vulnerability due to multiple stack-based buffer overflows that allow remote attackers to execute arbitrary code.
How do I fix CVE-2013-3607?
To fix CVE-2013-3607, update to the latest firmware released by Supermicro for the affected hardware models.
Which devices are affected by CVE-2013-3607?
CVE-2013-3607 affects multiple Supermicro devices including H8DC*, H8DG*, and X9DAX* among others.
What type of vulnerability is CVE-2013-3607?
CVE-2013-3607 is a stack-based buffer overflow vulnerability impacting the web interface of the IPMI implementation.
Can CVE-2013-3607 be exploited remotely?
Yes, CVE-2013-3607 can be exploited remotely by attackers to gain unauthorized access to the device.