First published: Wed Jun 24 2020(Updated: )
The web interface on Supermicro X10DRH-iT motherboards with BIOS 2.0a and IPMI firmware 03.40 allows remote attackers to exploit a cgi/config_user.cgi CSRF issue to add new admin users. The fixed versions are BIOS 3.2 and firmware 03.88.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Supermicro X10drh-it Bios | =2.0a | |
Supermicro X10drh-it Firmware | =3.40 | |
Supermicro X10DRH-iT | ||
All of | ||
Any of | ||
Supermicro X10drh-it Bios | =2.0a | |
Supermicro X10drh-it Firmware | =3.40 | |
Supermicro X10DRH-iT |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-15046 is a vulnerability in Supermicro X10DRH-iT motherboards with BIOS 2.0a and IPMI firmware 03.40 that allows remote attackers to exploit a CSRF issue and add new admin users.
CVE-2020-15046 has a severity rating of 8.8, which is classified as critical.
The web interface can be exploited through a CSRF issue in the cgi/config_user.cgi file.
The affected versions are BIOS 2.0a and IPMI firmware 03.40.
The fixed versions are BIOS 3.2 and IPMI firmware 03.88.