CVE-2023-33411: Path Traversal
A web server in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions up to 3.17.02, allows remote unauthenticated users to perform directory traversal, potentially disclosing sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-33411?
CVE-2023-33411 is classified as a high severity vulnerability due to its ability to allow remote unauthenticated users to perform directory traversal on affected devices.
How do I fix CVE-2023-33411?
To mitigate CVE-2023-33411, users should upgrade their firmware to a version higher than 3.17.02 as released by Supermicro.
What devices are affected by CVE-2023-33411?
CVE-2023-33411 affects Supermicro X11 and M11 based devices that utilize BMC firmware versions up to 3.17.02.
What does directory traversal mean in the context of CVE-2023-33411?
Directory traversal in CVE-2023-33411 refers to the capability of an attacker to access restricted files on the server without authentication by manipulating the URL.
Is CVE-2023-33411 an authenticated or unauthenticated vulnerability?
CVE-2023-33411 is an unauthenticated vulnerability, allowing access without any login credentials.