CVE-2013-3608: Input Validation
The web interface in the Intelligent Platform Management Interface (IPMI) implementation on Supermicro H8DC, H8DG, H8SCM-F, H8SGL-F, H8SM, X7SP, X8DT, X8SI, X9DAX-, X9DB, X9DR, X9QR, X9SBAA-F, X9SC, X9SPU-F, and X9SR devices allows remote authenticated users to execute arbitrary commands via shell metacharacters, as demonstrated by the IP address field in configdatetime.cgi.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-3608?
CVE-2013-3608 has a medium severity rating, allowing remote authenticated users to execute arbitrary commands.
How do I fix CVE-2013-3608?
To fix CVE-2013-3608, update your Supermicro hardware firmware to the latest version available from Supermicro's support.
Which Supermicro devices are affected by CVE-2013-3608?
CVE-2013-3608 affects various Supermicro devices in the H8, X7, X8, and X9 series.
Is CVE-2013-3608 an unpatched vulnerability?
Yes, CVE-2013-3608 is considered a significant vulnerability that requires firmware updates to patch.
What kind of attack can CVE-2013-3608 facilitate?
CVE-2013-3608 can allow an attacker to execute arbitrary commands on affected Supermicro devices.