Description
A shell-injection vulnerability in email notifications on Supermicro motherboards (such as H12DST-B before 03.10.35) allows remote attackers to inject execute arbitrary commands as root on the BMC.
Published: 2023-07-31
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-39854 A shell-injection vulnerability in email notifications on Supermicro motherboards (such as H12DST-B before 03.10.35) allows remote attackers to inject execute arbitrary commands as root on the BMC.
History

Tue, 22 Oct 2024 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Supermicro H12dgo-6 H12dgo-6 Firmware H12dgq-nt6 H12dgq-nt6 Firmware H12dsg-o-cpu H12dsg-o-cpu Firmware H12dsg-q-cpu6 H12dsg-q-cpu6 Firmware H12dsi-n6 H12dsi-n6 Firmware H12dsi-nt6 H12dsi-nt6 Firmware H12dst-b H12dst-b Firmware H12dsu-in H12dsu-in Firmware H12dsu-inr H12dsu-inr Firmware H12ssff-an6 H12ssff-an6 Firmware H12ssfr-an6 H12ssfr-an6 Firmware H12ssg-an6 H12ssg-an6 Firmware H12ssg-anp6 H12ssg-anp6 Firmware H12ssl-c H12ssl-c Firmware H12ssl-ct H12ssl-ct Firmware H12ssl-i H12ssl-i Firmware H12ssl-nt H12ssl-nt Firmware H12sst-ps H12sst-ps Firmware H12ssw-an6 H12ssw-an6 Firmware H12ssw-in H12ssw-in Firmware H12ssw-inl H12ssw-inl Firmware H12ssw-inr H12ssw-inr Firmware H12ssw-nt H12ssw-nt Firmware H12ssw-ntl H12ssw-ntl Firmware H12ssw-ntr H12ssw-ntr Firmware H13dsg-o-cpu H13dsg-o-cpu-d H13dsg-o-cpu-d Firmware H13dsg-o-cpu Firmware H13dsh H13dsh Firmware H13sae-mf H13sae-mf Firmware H13srd-f H13srd-f Firmware H13ssf H13ssf Firmware H13ssh H13ssh Firmware H13ssl-n H13ssl-n Firmware H13ssl-nt H13ssl-nt Firmware H13sst-g H13sst-g Firmware H13sst-gc H13sst-gc Firmware H13ssw H13ssw Firmware X12dai-n6 X12dai-n6 Firmware X12ddw-a6 X12ddw-a6 Firmware X12dgo-6 X12dgo-6 Firmware X12dgq-r X12dgq-r Firmware X12dgu X12dgu Firmware X12dhm-6 X12dhm-6 Firmware X12dpd-a6m25 X12dpd-a6m25 Firmware X12dpfr-an6 X12dpfr-an6 Firmware X12dpg-ar X12dpg-ar Firmware X12dpg-oa6 X12dpg-oa6-gd2 X12dpg-oa6-gd2 Firmware X12dpg-oa6 Firmware X12dpg-qbt6 X12dpg-qbt6 Firmware X12dpg-qr X12dpg-qr Firmware X12dpg-qt6 X12dpg-qt6 Firmware X12dpg-u6 X12dpg-u6 Firmware X12dpi-n6 X12dpi-n6 Firmware X12dpi-nt6 X12dpi-nt6 Firmware X12dpl-i6 X12dpl-i6 Firmware X12dpl-nt6 X12dpl-nt6 Firmware X12dpt-b6 X12dpt-b6 Firmware X12dpt-pt46 X12dpt-pt46 Firmware X12dpt-pt6 X12dpt-pt6 Firmware X12dpu-6 X12dpu-6 Firmware X12dsc-6 X12dsc-6 Firmware X12qch\+ X12qch\+ Firmware X12sae X12sae-5 X12sae-5 Firmware X12sae Firmware X12sca-5f X12sca-5f Firmware X12sca-f X12sca-f Firmware X12scq X12scq Firmware X12scv-lvds X12scv-lvds Firmware X12scv-w X12scv-w Firmware X12scz-f X12scz-f Firmware X12scz-qf X12scz-qf Firmware X12scz-tln4f X12scz-tln4f Firmware X12sdv-10c-sp6f X12sdv-10c-sp6f Firmware X12sdv-10c-spt4f X12sdv-10c-spt4f Firmware X12sdv-14c-spt8f X12sdv-14c-spt8f Firmware X12sdv-16c-spt8f X12sdv-16c-spt8f Firmware X12sdv-20c-spt8f X12sdv-20c-spt8f Firmware X12sdv-4c-sp6f X12sdv-4c-sp6f Firmware X12sdv-4c-spt4f X12sdv-4c-spt4f Firmware X12sdv-4c-spt8f X12sdv-4c-spt8f Firmware X12sdv-8c-sp6f X12sdv-8c-sp6f Firmware X12sdv-8c-spt4f X12sdv-8c-spt4f Firmware X12sdv-8c-spt8f X12sdv-8c-spt8f Firmware X12sdv-8ce-sp4f X12sdv-8ce-sp4f Firmware X12spa-tf X12spa-tf Firmware X12sped-f X12sped-f Firmware X12spg-nf X12spg-nf Firmware X12spi-tf X12spi-tf Firmware X12spl-f X12spl-f Firmware X12spl-ln4f X12spl-ln4f Firmware X12spm-ln4f X12spm-ln4f Firmware X12spm-ln6tf X12spm-ln6tf Firmware X12spm-tf X12spm-tf Firmware X12spo-f X12spo-f Firmware X12spo-ntf X12spo-ntf Firmware X12spt-g X12spt-g Firmware X12spt-gc X12spt-gc Firmware X12spt-pt X12spt-pt Firmware X12spw-f X12spw-f Firmware X12spw-tf X12spw-tf Firmware X12spz-ln4f X12spz-ln4f Firmware X12spz-spln6f X12spz-spln6f Firmware X12std-f X12std-f Firmware X12ste-f X12ste-f Firmware X12sth-f X12sth-f Firmware X12sth-ln4f X12sth-ln4f Firmware X12sth-sys X12sth-sys Firmware X12stl-f X12stl-f Firmware X12stl-if X12stl-if Firmware X12stn-c X12stn-c-wohs X12stn-c-wohs Firmware X12stn-c Firmware X12stn-e X12stn-e-wohs X12stn-e-wohs Firmware X12stn-e Firmware X12stn-h X12stn-h-wohs X12stn-h-wohs Firmware X12stn-h Firmware X12stn-l X12stn-l-wohs X12stn-l-wohs Firmware X12stn-l Firmware X12stw-f X12stw-f Firmware X12stw-tf X12stw-tf Firmware X13dai-t X13dai-t Firmware X13ddw-a X13ddw-a Firmware X13deg-oa X13deg-oa Firmware X13deg-oad X13deg-oad Firmware X13deg-pvc X13deg-pvc Firmware X13deg-qt X13deg-qt Firmware X13dei X13dei-t X13dei-t Firmware X13dei Firmware X13dem X13dem Firmware X13det-b X13det-b Firmware X13dgu X13dgu Firmware X13dsf-a X13dsf-a Firmware X13qeh\+ X13qeh\+ Firmware X13sae X13sae-f X13sae-f Firmware X13sae Firmware X13san-c X13san-c-wohs X13san-c-wohs Firmware X13san-c Firmware X13san-e X13san-e-wohs X13san-e-wohs Firmware X13san-e Firmware X13san-h X13san-h-wohs X13san-h-wohs Firmware X13san-h Firmware X13san-l X13san-l-wohs X13san-l-wohs Firmware X13san-l Firmware X13saq X13saq Firmware X13sav-lvds X13sav-lvds Firmware X13sav-ps X13sav-ps Firmware X13saz-f X13saz-f Firmware X13saz-q X13saz-q Firmware X13sedw-f X13sedw-f Firmware X13seed-f X13seed-f Firmware X13seed-sf X13seed-sf Firmware X13sefr-a X13sefr-a Firmware X13sei-f X13sei-f Firmware X13sei-tf X13sei-tf Firmware X13sem-f X13sem-f Firmware X13sem-tf X13sem-tf Firmware X13set-g X13set-g Firmware X13set-gc X13set-gc Firmware X13sew-f X13sew-f Firmware X13sew-tf X13sew-tf Firmware X13sra-tf X13sra-tf Firmware X13srn-e X13srn-e-wohs X13srn-e-wohs Firmware X13srn-e Firmware X13srn-h X13srn-h-wohs X13srn-h-wohs Firmware X13srn-h Firmware X13swa-tf X13swa-tf Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-10-22T18:08:38.401Z

Reserved: 2023-06-19T00:00:00.000Z

Link: CVE-2023-35861

cve-icon Vulnrichment

Updated: 2024-08-02T16:30:45.365Z

cve-icon NVD

Status : Modified

Published: 2023-07-31T13:15:09.833

Modified: 2024-11-21T08:08:51.000

Link: CVE-2023-35861

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses