CVE-2023-33413: High severity Supermicro M11sdv-4c-ln4f Firmware vulnerability
The configuration functionality in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions through 3.17.02, allows remote authenticated users to execute arbitrary commands.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict network access to the IPMI BMC interface on affected Supermicro X11 and M11 devices (configured remote authenticated users can execute arbitrary commands through firmware versions through 3.17.02).
Event History
Frequently Asked Questions
What is the severity of CVE-2023-33413?
CVE-2023-33413 has a critical severity rating due to its ability to allow remote authenticated users to execute arbitrary commands.
How do I fix CVE-2023-33413?
To fix CVE-2023-33413, upgrade the firmware of the affected Supermicro X11 and M11 devices to versions higher than 3.17.02.
What devices are affected by CVE-2023-33413?
CVE-2023-33413 affects Supermicro X11 and M11 based devices running firmware versions through 3.17.02.
Can CVE-2023-33413 be exploited without authentication?
No, CVE-2023-33413 can only be exploited by remote authenticated users.
What are the potential impacts of CVE-2023-33413?
The potential impacts of CVE-2023-33413 include unauthorized command execution and full control over the affected system.