CWE
20
Advisory Published
Updated

CVE-2013-3608: Input Validation

First published: Sun Sep 08 2013(Updated: )

The web interface in the Intelligent Platform Management Interface (IPMI) implementation on Supermicro H8DC*, H8DG*, H8SCM-F, H8SGL-F, H8SM*, X7SP*, X8DT*, X8SI*, X9DAX-*, X9DB*, X9DR*, X9QR*, X9SBAA-F, X9SC*, X9SPU-F, and X9SR* devices allows remote authenticated users to execute arbitrary commands via shell metacharacters, as demonstrated by the IP address field in config_date_time.cgi.

Credit: cret@cert.org

Affected SoftwareAffected VersionHow to fix
Supermicro H8DCL-6F
Supermicro H8DCL-IF
Supermicro H8DCT-HIBQF
Supermicro H8DCT-HLN4F
Supermicro H8DCT-IBQF
Supermicro H8DG6-F
Supermicro H8DGG-QF
Supermicro H8DGI-F
Supermicro H8DGT-HF
Supermicro H8DGT-HIBQF
Supermicro H8DGT-HLF
Supermicro H8DGT-HLIBQF
Supermicro H8DGU-F
Supermicro H8DGU-LN4F+
Supermicro H8SCM-F
Supermicro H8SGL-F
Supermicro H8SME-F
Supermicro H8SML-7
Supermicro H8SML-7F
Supermicro H8SML-I
Supermicro H8DCL-IF
Supermicro X7SPA-HF-D525
Supermicro X7SPA-HF-D525
Supermicro X7SPE-H-D525
Supermicro X7SPE-HF
Supermicro X7SPE-HF-D525
Supermicro X7SPT-DF-D525
Supermicro X7SPT-DF-D525+
Supermicro X8DTL-3F
Supermicro X8DTL-6F
Supermicro X8DTL-IF
Supermicro x8dtn+-f
Supermicro X8DTN+
Supermicro X8DTU-6F+
Supermicro X8DTU-6F+-LR
Supermicro X8DTU-6TF+
Supermicro x8dtu-6tf+-lr
Supermicro x8dtu-ln4f+
Supermicro X8DTU-LN4F+-LR
Supermicro X8SI6-F
Supermicro X8SIA Firmware
Supermicro X8SIE Firmware
Supermicro X8SIEx LN4F
Supermicro X8SIL Firmware
Supermicro X8SIT-F
Supermicro X8SIT-HF
Supermicro X8SIU-F
Supermicro X9DAX-7F-HFT
Supermicro X9DAX-7F
Supermicro X9DAX-7F
Supermicro X9DAX-7F
Supermicro X9DAX-7/IF-HFT Firmware
Supermicro X9DAX-7F
Supermicro X9DB3-F
Supermicro X9DB3/i-(TP)F
Supermicro X9DBI-F
Supermicro X9DBI-TPF
Supermicro X9DBL-3F
Supermicro X9DBL-IF
Supermicro X9DBU-3F
Supermicro X9DBU-IF
Supermicro X9DR3-F
Supermicro X9DR3-LN4F+
Supermicro X9DR7/E-LN4F Firmware
Supermicro X9QR7-TF JBOD
Supermicro X9DR7-TF+
Supermicro X9DRD-7JLNF
Supermicro X9DRD-7LN4F Series Firmware
Supermicro x9drd-7jln4f
Supermicro X9DRD-EF Firmware
Supermicro X9DRD-L/IF Firmware
Supermicro X9DRE-LN4F
Supermicro x9dre-tf+
Supermicro X9DRFF-7
Supermicro X9DRFF-7
Supermicro X9DRFF-7+
Supermicro X9DRFF-7G+
Supermicro X9DRFF-7T+
Supermicro X9DRFF-7TG+
Supermicro X9DRFF-I+
Supermicro X9DRFF-IG+
Supermicro X9DRFF-IT+
Supermicro X9 DRFF-ITG+
Supermicro X9DRFR
Supermicro X9DRG-HF
Supermicro X9DRG-HF+
Supermicro x9drg-h(t)f
Supermicro x9drg-htf+
Supermicro X9DRH-7TF
Supermicro X9DRH-7/i(T)F
Supermicro X9DRH-IF
Supermicro X9DRH-7/i(T)F
Supermicro X9DRi-F
Supermicro X9DRI-LN4F+
Supermicro X9DRL-3F
Supermicro X9DRL-EF
Supermicro X9DRL-IF
Supermicro X9DRT-F
Supermicro X9DRT-H6F
Supermicro X9DRT-H6IBFF
Supermicro X9DRT-IBQF
Supermicro X9DRT-HF+
Supermicro x9drt-h series
Supermicro X9DRT-IBQF
Supermicro X9DRW-3LN4F+
Supermicro X9DRW-3TF+
Supermicro X9DRW-7TPF+
Supermicro X9DRW-ITPF+
Supermicro X9DRX+-F
Supermicro X9QR7-TF JBOD
Supermicro X9QR7-TF+
Supermicro X9QR7-TF JBOD
Supermicro X9QRI-F+
Supermicro X9QRI-F+
Supermicro X9SBAA-F
Supermicro X9SCA-F
Supermicro X9SCF-F
Supermicro X9SC Series
Supermicro X9SC Series
Supermicro X9SCI-LN4(F) Firmware
Supermicro X9SCL-F
Supermicro X9SC Series
Supermicro X9SC Series
Supermicro X9SCM-IIF
Supermicro X9SPU-F
Supermicro X9SRD-F Firmware
Supermicro X9SRE/i Series
Supermicro X9SRE/i Series
Supermicro X9SRG-F
Supermicro X9SRI-3F
Supermicro X9SRI-F
Supermicro X9SRL-F Firmware
Supermicro X9SRW-F Firmware

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2013-3608?

    CVE-2013-3608 has a medium severity rating, allowing remote authenticated users to execute arbitrary commands.

  • How do I fix CVE-2013-3608?

    To fix CVE-2013-3608, update your Supermicro hardware firmware to the latest version available from Supermicro's support.

  • Which Supermicro devices are affected by CVE-2013-3608?

    CVE-2013-3608 affects various Supermicro devices in the H8, X7, X8, and X9 series.

  • Is CVE-2013-3608 an unpatched vulnerability?

    Yes, CVE-2013-3608 is considered a significant vulnerability that requires firmware updates to patch.

  • What kind of attack can CVE-2013-3608 facilitate?

    CVE-2013-3608 can allow an attacker to execute arbitrary commands on affected Supermicro devices.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203