CVE-2023-40285: XSS
Published Mar 27, 2024
·Updated
An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue.
Affected Software
9 affected components
Supermicro X11SSM-F
Supermicro X11SAE-F
Supermicro X11SSE-F
All of the following
Supermicro X11ssm-f Firmware=1.66
Supermicro X11SSM-F
All of the following
Supermicro X11sae-f Firmware=1.66
Supermicro X11SAE-F
All of the following
Supermicro X11sse-f Firmware=1.66
Supermicro X11SSE-F
Event History
Mar 27, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-40285?
CVE-2023-40285 is considered a medium severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
2
How can I mitigate CVE-2023-40285?
Mitigating CVE-2023-40285 involves updating the affected Supermicro devices to the latest firmware version provided by Supermicro.
3
What products are affected by CVE-2023-40285?
CVE-2023-40285 affects Supermicro X11SSM-F, X11SAE-F, and X11SSE-F devices specifically.
4
What kind of attack does CVE-2023-40285 pertain to?
CVE-2023-40285 pertains to a cross-site scripting (XSS) vulnerability that could allow an attacker to execute malicious scripts.
5
Is there a patch available for CVE-2023-40285?
Yes, Supermicro has released a patch to address CVE-2023-40285, which is available through their support website.