CVE-2013-3608
Last modified
CVE-2013-3608 is a vulnerability of currently unknown severity. The web interface in the Intelligent Platform Management Interface (IPMI) implementation on Supermicro H8DC*, H8DG*, H8SCM-F, H8SGL-F, H8SM*, X7SP*, X8DT*, X8SI*, X9DAX-*, X9DB*, X9DR*, X9QR*, X9SBAA-F, X9SC*, X9SPU-F, and X9SR* devices allows remote authenticated users to execute arbitrary commands via shell metacharacters, as demonstrated by the IP address field in config_date_time.cgi.. EPSS estimates a 6.41% chance of exploitation in the next 30 days.
Description
The web interface in the Intelligent Platform Management Interface (IPMI) implementation on Supermicro H8DC*, H8DG*, H8SCM-F, H8SGL-F, H8SM*, X7SP*, X8DT*, X8SI*, X9DAX-*, X9DB*, X9DR*, X9QR*, X9SBAA-F, X9SC*, X9SPU-F, and X9SR* devices allows remote authenticated users to execute arbitrary commands via shell metacharacters, as demonstrated by the IP address field in config_date_time.cgi.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Supermicro | H8dcl-6f | All versions |
| Supermicro | H8dcl-If | All versions |
| Supermicro | H8dct-Hibqf | All versions |
| Supermicro | H8dct-Hln4f | All versions |
| Supermicro | H8dct-Ibqf | All versions |
| Supermicro | H8dg6-F | All versions |
| Supermicro | H8dgg-Qf | All versions |
| Supermicro | H8dgi-F | All versions |
| Supermicro | H8dgt-Hf | All versions |
| Supermicro | H8dgt-Hibqf | All versions |
| Supermicro | H8dgt-Hlf | All versions |
| Supermicro | H8dgt-Hlibqf | All versions |
| Supermicro | H8dgu-F | All versions |
| Supermicro | H8dgu-Ln4f\+ | All versions |
| Supermicro | H8scm-F | All versions |
| Supermicro | H8sgl-F | All versions |
| Supermicro | H8sme-F | All versions |
| Supermicro | H8sml-7 | All versions |
| Supermicro | H8sml-7f | All versions |
| Supermicro | H8sml-I | All versions |
| Supermicro | H8sml-If | All versions |
| Supermicro | X7spa-Hf | All versions |
| Supermicro | X7spa-Hf-D525 | All versions |
| Supermicro | X7spe-H-D525 | All versions |
| Supermicro | X7spe-Hf | All versions |
| Supermicro | X7spe-Hf-D525 | All versions |
| Supermicro | X7spt-Df-D525 | All versions |
| Supermicro | X7spt-Df-D525\+ | All versions |
| Supermicro | X8dtl-3f | All versions |
| Supermicro | X8dtl-6f | All versions |
| Supermicro | X8dtl-If | All versions |
| Supermicro | X8dtn\+-F | All versions |
| Supermicro | X8dtn\+-F-Lr | All versions |
| Supermicro | X8dtu-6f\+ | All versions |
| Supermicro | X8dtu-6f\+-Lr | All versions |
| Supermicro | X8dtu-6tf\+ | All versions |
| Supermicro | X8dtu-6tf\+-Lr | All versions |
| Supermicro | X8dtu-Ln4f\+ | All versions |
| Supermicro | X8dtu-Ln4f\+-Lr | All versions |
| Supermicro | X8si6-F | All versions |
| Supermicro | X8sia-F | All versions |
| Supermicro | X8sie-F | All versions |
| Supermicro | X8sie-Ln4f | All versions |
| Supermicro | X8sil-F | All versions |
| Supermicro | X8sit-F | All versions |
| Supermicro | X8sit-Hf | All versions |
| Supermicro | X8siu-F | All versions |
| Supermicro | X9dax-7f | All versions |
| Supermicro | X9dax-7f-Hft | All versions |
| Supermicro | X9dax-7tf | All versions |
Showing 50 of 133 affected configurations. See NVD for the full list.
References
- http://www.kb.cert.org/vuls/id/648646US Government Resource
- http://www.kb.cert.org/vuls/id/648646US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-3608?
How severe is CVE-2013-3608?
How do I fix CVE-2013-3608?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2013
- CVE-2013-3602SQL injection vulnerability in admindocumentworker.jsp in Co…
- CVE-2013-3603Cross-site scripting (XSS) vulnerability in Coursemill Learn…
- CVE-2013-3604Multiple cross-site scripting (XSS) vulnerabilities in Cours…
- CVE-2013-3605Cross-site request forgery (CSRF) vulnerability in Coursemil…
- CVE-2013-3606The login page in the GoAhead web server on Dell PowerConnec…
- CVE-2013-3607Multiple stack-based buffer overflows in the web interface i…
- CVE-2013-3609The web interface in the Intelligent Platform Management Int…
- CVE-2013-3610qis/QIS_finish.htm on the ASUS RT-N10E router with firmware …
- CVE-2013-3611Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2013-3612Dahua DVR appliances have a hardcoded password for (1) the r…
- CVE-2013-3613Dahua DVR appliances do not properly restrict UPnP requests,…
- CVE-2013-3614Dahua DVR appliances have a small value for the maximum pass…
Are you affected by CVE-2013-3608?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
