A shell-injection vulnerability in email notifications on Supermicro motherboards (such as H12DST-B before 03.10.35) allows remote attackers to inject execute arbitrary commands as root on the BMC.

Project Subscriptions

Vendors Products
Supermicro Subscribe
H12dgo-6 Subscribe
H12dgo-6 Firmware Subscribe
H12dgq-nt6 Subscribe
H12dgq-nt6 Firmware Subscribe
H12dsg-o-cpu Subscribe
H12dsg-o-cpu Firmware Subscribe
H12dsg-q-cpu6 Subscribe
H12dsg-q-cpu6 Firmware Subscribe
H12dsi-n6 Subscribe
H12dsi-n6 Firmware Subscribe
H12dsi-nt6 Subscribe
H12dsi-nt6 Firmware Subscribe
H12dst-b Subscribe
H12dst-b Firmware Subscribe
H12dsu-in Subscribe
H12dsu-in Firmware Subscribe
H12dsu-inr Subscribe
H12dsu-inr Firmware Subscribe
H12ssff-an6 Subscribe
H12ssff-an6 Firmware Subscribe
H12ssfr-an6 Subscribe
H12ssfr-an6 Firmware Subscribe
H12ssg-an6 Subscribe
H12ssg-an6 Firmware Subscribe
H12ssg-anp6 Subscribe
H12ssg-anp6 Firmware Subscribe
H12ssl-c Subscribe
H12ssl-c Firmware Subscribe
H12ssl-ct Subscribe
H12ssl-ct Firmware Subscribe
H12ssl-i Subscribe
H12ssl-i Firmware Subscribe
H12ssl-nt Subscribe
H12ssl-nt Firmware Subscribe
H12sst-ps Subscribe
H12sst-ps Firmware Subscribe
H12ssw-an6 Subscribe
H12ssw-an6 Firmware Subscribe
H12ssw-in Subscribe
H12ssw-in Firmware Subscribe
H12ssw-inl Subscribe
H12ssw-inl Firmware Subscribe
H12ssw-inr Subscribe
H12ssw-inr Firmware Subscribe
H12ssw-nt Subscribe
H12ssw-nt Firmware Subscribe
H12ssw-ntl Subscribe
H12ssw-ntl Firmware Subscribe
H12ssw-ntr Subscribe
H12ssw-ntr Firmware Subscribe
H13dsg-o-cpu Subscribe
H13dsg-o-cpu-d Subscribe
H13dsg-o-cpu-d Firmware Subscribe
H13dsg-o-cpu Firmware Subscribe
H13dsh Firmware Subscribe
H13sae-mf Subscribe
H13sae-mf Firmware Subscribe
H13srd-f Subscribe
H13srd-f Firmware Subscribe
H13ssf Firmware Subscribe
H13ssh Firmware Subscribe
H13ssl-n Subscribe
H13ssl-n Firmware Subscribe
H13ssl-nt Subscribe
H13ssl-nt Firmware Subscribe
H13sst-g Subscribe
H13sst-g Firmware Subscribe
H13sst-gc Subscribe
H13sst-gc Firmware Subscribe
H13ssw Firmware Subscribe
X12dai-n6 Subscribe
X12dai-n6 Firmware Subscribe
X12ddw-a6 Subscribe
X12ddw-a6 Firmware Subscribe
X12dgo-6 Subscribe
X12dgo-6 Firmware Subscribe
X12dgq-r Subscribe
X12dgq-r Firmware Subscribe
X12dgu Firmware Subscribe
X12dhm-6 Subscribe
X12dhm-6 Firmware Subscribe
X12dpd-a6m25 Subscribe
X12dpd-a6m25 Firmware Subscribe
X12dpfr-an6 Subscribe
X12dpfr-an6 Firmware Subscribe
X12dpg-ar Subscribe
X12dpg-ar Firmware Subscribe
X12dpg-oa6 Subscribe
X12dpg-oa6-gd2 Subscribe
X12dpg-oa6-gd2 Firmware Subscribe
X12dpg-oa6 Firmware Subscribe
X12dpg-qbt6 Subscribe
X12dpg-qbt6 Firmware Subscribe
X12dpg-qr Subscribe
X12dpg-qr Firmware Subscribe
X12dpg-qt6 Subscribe
X12dpg-qt6 Firmware Subscribe
X12dpg-u6 Subscribe
X12dpg-u6 Firmware Subscribe
X12dpi-n6 Subscribe
X12dpi-n6 Firmware Subscribe
X12dpi-nt6 Subscribe
X12dpi-nt6 Firmware Subscribe
X12dpl-i6 Subscribe
X12dpl-i6 Firmware Subscribe
X12dpl-nt6 Subscribe
X12dpl-nt6 Firmware Subscribe
X12dpt-b6 Subscribe
X12dpt-b6 Firmware Subscribe
X12dpt-pt46 Subscribe
X12dpt-pt46 Firmware Subscribe
X12dpt-pt6 Subscribe
X12dpt-pt6 Firmware Subscribe
X12dpu-6 Subscribe
X12dpu-6 Firmware Subscribe
X12dsc-6 Subscribe
X12dsc-6 Firmware Subscribe
X12qch\+ Subscribe
X12qch\+ Firmware Subscribe
X12sae-5 Subscribe
X12sae-5 Firmware Subscribe
X12sae Firmware Subscribe
X12sca-5f Subscribe
X12sca-5f Firmware Subscribe
X12sca-f Subscribe
X12sca-f Firmware Subscribe
X12scq Firmware Subscribe
X12scv-lvds Subscribe
X12scv-lvds Firmware Subscribe
X12scv-w Subscribe
X12scv-w Firmware Subscribe
X12scz-f Subscribe
X12scz-f Firmware Subscribe
X12scz-qf Subscribe
X12scz-qf Firmware Subscribe
X12scz-tln4f Subscribe
X12scz-tln4f Firmware Subscribe
X12sdv-10c-sp6f Subscribe
X12sdv-10c-sp6f Firmware Subscribe
X12sdv-10c-spt4f Subscribe
X12sdv-10c-spt4f Firmware Subscribe
X12sdv-14c-spt8f Subscribe
X12sdv-14c-spt8f Firmware Subscribe
X12sdv-16c-spt8f Subscribe
X12sdv-16c-spt8f Firmware Subscribe
X12sdv-20c-spt8f Subscribe
X12sdv-20c-spt8f Firmware Subscribe
X12sdv-4c-sp6f Subscribe
X12sdv-4c-sp6f Firmware Subscribe
X12sdv-4c-spt4f Subscribe
X12sdv-4c-spt4f Firmware Subscribe
X12sdv-4c-spt8f Subscribe
X12sdv-4c-spt8f Firmware Subscribe
X12sdv-8c-sp6f Subscribe
X12sdv-8c-sp6f Firmware Subscribe
X12sdv-8c-spt4f Subscribe
X12sdv-8c-spt4f Firmware Subscribe
X12sdv-8c-spt8f Subscribe
X12sdv-8c-spt8f Firmware Subscribe
X12sdv-8ce-sp4f Subscribe
X12sdv-8ce-sp4f Firmware Subscribe
X12spa-tf Subscribe
X12spa-tf Firmware Subscribe
X12sped-f Subscribe
X12sped-f Firmware Subscribe
X12spg-nf Subscribe
X12spg-nf Firmware Subscribe
X12spi-tf Subscribe
X12spi-tf Firmware Subscribe
X12spl-f Subscribe
X12spl-f Firmware Subscribe
X12spl-ln4f Subscribe
X12spl-ln4f Firmware Subscribe
X12spm-ln4f Subscribe
X12spm-ln4f Firmware Subscribe
X12spm-ln6tf Subscribe
X12spm-ln6tf Firmware Subscribe
X12spm-tf Subscribe
X12spm-tf Firmware Subscribe
X12spo-f Subscribe
X12spo-f Firmware Subscribe
X12spo-ntf Subscribe
X12spo-ntf Firmware Subscribe
X12spt-g Subscribe
X12spt-g Firmware Subscribe
X12spt-gc Subscribe
X12spt-gc Firmware Subscribe
X12spt-pt Subscribe
X12spt-pt Firmware Subscribe
X12spw-f Subscribe
X12spw-f Firmware Subscribe
X12spw-tf Subscribe
X12spw-tf Firmware Subscribe
X12spz-ln4f Subscribe
X12spz-ln4f Firmware Subscribe
X12spz-spln6f Subscribe
X12spz-spln6f Firmware Subscribe
X12std-f Subscribe
X12std-f Firmware Subscribe
X12ste-f Subscribe
X12ste-f Firmware Subscribe
X12sth-f Subscribe
X12sth-f Firmware Subscribe
X12sth-ln4f Subscribe
X12sth-ln4f Firmware Subscribe
X12sth-sys Subscribe
X12sth-sys Firmware Subscribe
X12stl-f Subscribe
X12stl-f Firmware Subscribe
X12stl-if Subscribe
X12stl-if Firmware Subscribe
X12stn-c Subscribe
X12stn-c-wohs Subscribe
X12stn-c-wohs Firmware Subscribe
X12stn-c Firmware Subscribe
X12stn-e Subscribe
X12stn-e-wohs Subscribe
X12stn-e-wohs Firmware Subscribe
X12stn-e Firmware Subscribe
X12stn-h Subscribe
X12stn-h-wohs Subscribe
X12stn-h-wohs Firmware Subscribe
X12stn-h Firmware Subscribe
X12stn-l Subscribe
X12stn-l-wohs Subscribe
X12stn-l-wohs Firmware Subscribe
X12stn-l Firmware Subscribe
X12stw-f Subscribe
X12stw-f Firmware Subscribe
X12stw-tf Subscribe
X12stw-tf Firmware Subscribe
X13dai-t Subscribe
X13dai-t Firmware Subscribe
X13ddw-a Subscribe
X13ddw-a Firmware Subscribe
X13deg-oa Subscribe
X13deg-oa Firmware Subscribe
X13deg-oad Subscribe
X13deg-oad Firmware Subscribe
X13deg-pvc Subscribe
X13deg-pvc Firmware Subscribe
X13deg-qt Subscribe
X13deg-qt Firmware Subscribe
X13dei-t Subscribe
X13dei-t Firmware Subscribe
X13dei Firmware Subscribe
X13dem Firmware Subscribe
X13det-b Subscribe
X13det-b Firmware Subscribe
X13dgu Firmware Subscribe
X13dsf-a Subscribe
X13dsf-a Firmware Subscribe
X13qeh\+ Subscribe
X13qeh\+ Firmware Subscribe
X13sae-f Subscribe
X13sae-f Firmware Subscribe
X13sae Firmware Subscribe
X13san-c Subscribe
X13san-c-wohs Subscribe
X13san-c-wohs Firmware Subscribe
X13san-c Firmware Subscribe
X13san-e Subscribe
X13san-e-wohs Subscribe
X13san-e-wohs Firmware Subscribe
X13san-e Firmware Subscribe
X13san-h Subscribe
X13san-h-wohs Subscribe
X13san-h-wohs Firmware Subscribe
X13san-h Firmware Subscribe
X13san-l Subscribe
X13san-l-wohs Subscribe
X13san-l-wohs Firmware Subscribe
X13san-l Firmware Subscribe
X13saq Firmware Subscribe
X13sav-lvds Subscribe
X13sav-lvds Firmware Subscribe
X13sav-ps Subscribe
X13sav-ps Firmware Subscribe
X13saz-f Subscribe
X13saz-f Firmware Subscribe
X13saz-q Subscribe
X13saz-q Firmware Subscribe
X13sedw-f Subscribe
X13sedw-f Firmware Subscribe
X13seed-f Subscribe
X13seed-f Firmware Subscribe
X13seed-sf Subscribe
X13seed-sf Firmware Subscribe
X13sefr-a Subscribe
X13sefr-a Firmware Subscribe
X13sei-f Subscribe
X13sei-f Firmware Subscribe
X13sei-tf Subscribe
X13sei-tf Firmware Subscribe
X13sem-f Subscribe
X13sem-f Firmware Subscribe
X13sem-tf Subscribe
X13sem-tf Firmware Subscribe
X13set-g Subscribe
X13set-g Firmware Subscribe
X13set-gc Subscribe
X13set-gc Firmware Subscribe
X13sew-f Subscribe
X13sew-f Firmware Subscribe
X13sew-tf Subscribe
X13sew-tf Firmware Subscribe
X13sra-tf Subscribe
X13sra-tf Firmware Subscribe
X13srn-e Subscribe
X13srn-e-wohs Subscribe
X13srn-e-wohs Firmware Subscribe
X13srn-e Firmware Subscribe
X13srn-h Subscribe
X13srn-h-wohs Subscribe
X13srn-h-wohs Firmware Subscribe
X13srn-h Firmware Subscribe
X13swa-tf Subscribe
X13swa-tf Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2023-39854 A shell-injection vulnerability in email notifications on Supermicro motherboards (such as H12DST-B before 03.10.35) allows remote attackers to inject execute arbitrary commands as root on the BMC.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 22 Oct 2024 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-10-22T18:08:38.401Z

Reserved: 2023-06-19T00:00:00

Link: CVE-2023-35861

cve-icon Vulnrichment

Updated: 2024-08-02T16:30:45.365Z

cve-icon NVD

Status : Modified

Published: 2023-07-31T13:15:09.833

Modified: 2024-11-21T08:08:51.000

Link: CVE-2023-35861

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses