SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2013-3607

Multiple stack-based buffer overflows in the web interface in the Intelligent Platform Management Interface (IPMI) implementation on Supermicro H8DC*, H8DG*, H8SCM-F, H8SGL-F, H8SM*, X7SP*, X8DT*, X8SI*, X9DAX-*, X9DB*, X9DR*, X9QR*, X9SBAA-F, X9SC*,…

HIGH 10.0EPSS 9.73%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (9.73%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Multiple stack-based buffer overflows in the web interface in the Intelligent Platform Management Interface (IPMI) implementation on Supermicro H8DC*, H8DG*, H8SCM-F, H8SGL-F, H8SM*, X7SP*, X8DT*, X8SI*, X9DAX-*, X9DB*, X9DR*, X9QR*, X9SBAA-F, X9SC*, X9SPU-F, and X9SR* devices allow remote attackers to execute arbitrary code on the Baseboard Management Controller (BMC), as demonstrated by the (1) username or (2) password field in login.cgi.

CVSS 2.0
10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
9.73% probability · 95th percentile
CISA KEV
Not listed
Weakness
CWE-119
Affected
supermicro/h8dcl-6f · supermicro/h8dcl-if · supermicro/h8dct-hibqf · supermicro/h8dct-hln4f · supermicro/h8dct-ibqf · supermicro/h8dg6-f · supermicro/h8dgg-qf · supermicro/h8dgi-f · supermicro/h8dgt-hf · supermicro/h8dgt-hibqf · supermicro/h8dgt-hlf · supermicro/h8dgt-hlibqf · supermicro/h8dgu-f · supermicro/h8dgu-ln4f\+ · supermicro/h8scm-f · supermicro/h8sgl-f · supermicro/h8sme-f · supermicro/h8sml-7 · supermicro/h8sml-7f · supermicro/h8sml-i · +40 more
Source
cret@cert.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.