CVE-2013-3609: Input Validation
The web interface in the Intelligent Platform Management Interface (IPMI) implementation on Supermicro H8DC, H8DG, H8SCM-F, H8SGL-F, H8SM, X7SP, X8DT, X8SI, X9DAX-, X9DB, X9DR, X9QR, X9SBAA-F, X9SC, X9SPU-F, and X9SR devices relies on JavaScript code on the client for authorization checks, which allows remote authenticated users to bypass intended access restrictions via a crafted request, related to the PrivilegeCallBack function.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-3609?
CVE-2013-3609 is classified as a high severity vulnerability due to its potential impact on system security.
How do I fix CVE-2013-3609?
To fix CVE-2013-3609, users should update to the latest firmware version provided by Supermicro that addresses this vulnerability.
What types of devices are affected by CVE-2013-3609?
CVE-2013-3609 affects various Supermicro devices including models from the H8, X7, X8, and X9 series.
What is the nature of CVE-2013-3609 vulnerability?
CVE-2013-3609 is a security flaw in the IPMI web interface that improperly handles authorization checks using client-side JavaScript.
Can CVE-2013-3609 be exploited remotely?
Yes, CVE-2013-3609 can be exploited remotely, allowing attackers to potentially gain unauthorized access to the affected devices.