CVE-2024-36435: Buffer Overflow
An issue was discovered on Supermicro BMC firmware in select X11, X12, H12, B12, X13, H13, and B13 motherboards (and CMM6 modules). An unauthenticated user can post crafted data to the interface that triggers a stack buffer overflow, and may lead to arbitrary remote code execution on a BMC.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-36435?
CVE-2024-36435 is considered a critical vulnerability due to its potential for arbitrary remote code execution.
How do I fix CVE-2024-36435?
To mitigate CVE-2024-36435, update the Supermicro BMC firmware to the latest version provided by Supermicro.
What systems are affected by CVE-2024-36435?
CVE-2024-36435 affects select Supermicro motherboards, specifically X11, X12, H12, B12, X13, H13, and B13 models, along with CMM6 modules.
What type of attack does CVE-2024-36435 exploit?
CVE-2024-36435 exploits a stack buffer overflow vulnerability that allows unauthenticated users to execute arbitrary code remotely.
Is CVE-2024-36435 a local or remote vulnerability?
CVE-2024-36435 is classified as a remote vulnerability, as it can be exploited without local access to the affected systems.