CVE-2023-40290: XSS
Published Mar 27, 2024
·Updated
An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue that affects Internet Explorer 11 on Windows.
Affected Software
10 affected components
Supermicro X11SSM-F
Supermicro X11SAE-F
Supermicro X11SSE-F
Microsoft Internet Explorer
All of the following
Supermicro X11ssm-f Firmware=1.66
Supermicro X11SSM-F
All of the following
Supermicro X11sae-f Firmware=1.66
Supermicro X11SAE-F
All of the following
Supermicro X11sse-f Firmware=1.66
Supermicro X11SSE-F
Event History
Mar 27, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-40290?
CVE-2023-40290 is considered a moderate severity vulnerability due to its potential for XSS exploitation.
2
How do I fix CVE-2023-40290?
To fix CVE-2023-40290, users should ensure they apply the latest firmware updates provided by Supermicro for affected devices.
3
What devices are affected by CVE-2023-40290?
CVE-2023-40290 affects Supermicro X11SSM-F, X11SAE-F, and X11SSE-F devices as well as Internet Explorer 11 on Windows.
4
What type of vulnerability is CVE-2023-40290?
CVE-2023-40290 is an XSS (Cross-Site Scripting) vulnerability.
5
Can CVE-2023-40290 be exploited remotely?
Yes, CVE-2023-40290 can potentially be exploited remotely through crafted web content.