CVE-2020-15046: CSRF
Published Jun 24, 2020
·Updated
The web interface on Supermicro X10DRH-iT motherboards with BIOS 2.0a and IPMI firmware 03.40 allows remote attackers to exploit a cgi/configuser.cgi CSRF issue to add new admin users. The fixed versions are BIOS 3.2 and firmware 03.88.
Affected Software
6 affected components
Supermicro X10drh-it Bios=2.0a
Supermicro X10drh-it Firmware=3.40
Supermicro X10DRH-iT
All of the following
Any of the following
Supermicro X10drh-it Bios=2.0a
Supermicro X10drh-it Firmware=3.40
Supermicro X10DRH-iT
Event History
Jun 24, 2020
CVE Published
via MITRE·10:25 PM
Data Sourced
via MITRE·10:25 PM
Description
Frequently Asked Questions
1
What is CVE-2020-15046?
CVE-2020-15046 is a vulnerability in Supermicro X10DRH-iT motherboards with BIOS 2.0a and IPMI firmware 03.40 that allows remote attackers to exploit a CSRF issue and add new admin users.
2
How severe is CVE-2020-15046?
CVE-2020-15046 has a severity rating of 8.8, which is classified as critical.
3
How can the web interface on Supermicro X10DRH-iT motherboards be exploited?
The web interface can be exploited through a CSRF issue in the cgi/config_user.cgi file.
4
What are the affected versions of the BIOS and firmware?
The affected versions are BIOS 2.0a and IPMI firmware 03.40.
5
What are the fixed versions of the BIOS and firmware?
The fixed versions are BIOS 3.2 and IPMI firmware 03.88.