CVE-2013-3609
Last modified
CVE-2013-3609 is a vulnerability of currently unknown severity. The web interface in the Intelligent Platform Management Interface (IPMI) implementation on Supermicro H8DC*, H8DG*, H8SCM-F, H8SGL-F, H8SM*, X7SP*, X8DT*, X8SI*, X9DAX-*, X9DB*, X9DR*, X9QR*, X9SBAA-F, X9SC*, X9SPU-F, and X9SR* devices relies on JavaScript code on the client for authorization checks, which allows remote authenticated users to bypass intended access restrictions via a crafted request, related to the PrivilegeCallBack function.. EPSS estimates a 5.31% chance of exploitation in the next 30 days.
Description
The web interface in the Intelligent Platform Management Interface (IPMI) implementation on Supermicro H8DC*, H8DG*, H8SCM-F, H8SGL-F, H8SM*, X7SP*, X8DT*, X8SI*, X9DAX-*, X9DB*, X9DR*, X9QR*, X9SBAA-F, X9SC*, X9SPU-F, and X9SR* devices relies on JavaScript code on the client for authorization checks, which allows remote authenticated users to bypass intended access restrictions via a crafted request, related to the PrivilegeCallBack function.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Supermicro | H8dcl-6f | All versions |
| Supermicro | H8dcl-If | All versions |
| Supermicro | H8dct-Hibqf | All versions |
| Supermicro | H8dct-Hln4f | All versions |
| Supermicro | H8dct-Ibqf | All versions |
| Supermicro | H8dg6-F | All versions |
| Supermicro | H8dgg-Qf | All versions |
| Supermicro | H8dgi-F | All versions |
| Supermicro | H8dgt-Hf | All versions |
| Supermicro | H8dgt-Hibqf | All versions |
| Supermicro | H8dgt-Hlf | All versions |
| Supermicro | H8dgt-Hlibqf | All versions |
| Supermicro | H8dgu-F | All versions |
| Supermicro | H8dgu-Ln4f\+ | All versions |
| Supermicro | H8scm-F | All versions |
| Supermicro | H8sgl-F | All versions |
| Supermicro | H8sme-F | All versions |
| Supermicro | H8sml-7 | All versions |
| Supermicro | H8sml-7f | All versions |
| Supermicro | H8sml-I | All versions |
| Supermicro | H8sml-If | All versions |
| Supermicro | X7spa-Hf | All versions |
| Supermicro | X7spa-Hf-D525 | All versions |
| Supermicro | X7spe-H-D525 | All versions |
| Supermicro | X7spe-Hf | All versions |
| Supermicro | X7spe-Hf-D525 | All versions |
| Supermicro | X7spt-Df-D525 | All versions |
| Supermicro | X7spt-Df-D525\+ | All versions |
| Supermicro | X8dtl-3f | All versions |
| Supermicro | X8dtl-6f | All versions |
| Supermicro | X8dtl-If | All versions |
| Supermicro | X8dtn\+-F | All versions |
| Supermicro | X8dtn\+-F-Lr | All versions |
| Supermicro | X8dtu-6f\+ | All versions |
| Supermicro | X8dtu-6f\+-Lr | All versions |
| Supermicro | X8dtu-6tf\+ | All versions |
| Supermicro | X8dtu-6tf\+-Lr | All versions |
| Supermicro | X8dtu-Ln4f\+ | All versions |
| Supermicro | X8dtu-Ln4f\+-Lr | All versions |
| Supermicro | X8si6-F | All versions |
| Supermicro | X8sia-F | All versions |
| Supermicro | X8sie-F | All versions |
| Supermicro | X8sie-Ln4f | All versions |
| Supermicro | X8sil-F | All versions |
| Supermicro | X8sit-F | All versions |
| Supermicro | X8sit-Hf | All versions |
| Supermicro | X8siu-F | All versions |
| Supermicro | X9dax-7f | All versions |
| Supermicro | X9dax-7f-Hft | All versions |
| Supermicro | X9dax-7tf | All versions |
Showing 50 of 133 affected configurations. See NVD for the full list.
References
- http://www.kb.cert.org/vuls/id/648646US Government Resource
- http://www.kb.cert.org/vuls/id/648646US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-3609?
How severe is CVE-2013-3609?
How do I fix CVE-2013-3609?
Are you affected by CVE-2013-3609?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
