CVE-2023-33412: High severity Supermicro M11sdv-4c-ln4f Firmware vulnerability
The web interface in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions before 3.17.02, allows remote authenticated users to execute arbitrary commands via a crafted request targeting vulnerable cgi endpoints.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Supermicro IPMI BMC (Intelligent Platform Management Interface)to a version that resolves this vulnerability.Fixed in 3.17.02
Event History
Frequently Asked Questions
What is the severity of CVE-2023-33412?
CVE-2023-33412 has a severity rating of high due to the potential for remote authenticated users to execute arbitrary commands via crafted requests.
How do I fix CVE-2023-33412?
To fix CVE-2023-33412, update the firmware of the affected Supermicro devices to version 3.17.02 or later.
What products are affected by CVE-2023-33412?
CVE-2023-33412 affects Supermicro X11 and M11 based devices with firmware versions prior to 3.17.02.
Can CVE-2023-33412 be exploited remotely?
Yes, CVE-2023-33412 can be exploited remotely by authenticated users.
What type of vulnerability is CVE-2023-33412?
CVE-2023-33412 is a command injection vulnerability affecting the web interface of the Intelligent Platform Management Interface (IPMI) on specific Supermicro devices.