CVE-2022-43309

MEDIUMCVSS 5.5/10EPSS 0.18%

Last modified

CVE-2022-43309 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. Supermicro X11SSL-CF HW Rev 1.01, BMC firmware v1.63 was discovered to contain insecure permissions.. EPSS estimates a 0.18% chance of exploitation in the next 30 days.

Description

Supermicro X11SSL-CF HW Rev 1.01, BMC firmware v1.63 was discovered to contain insecure permissions.

Metrics

CVSS 3.1
5.5/10

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

EPSS Probability
0.18%

7.6th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
SupermicroX11ssl-Cf Firmware1.63
SupermicroX11dac FirmwareAll versions
SupermicroX11dai-N FirmwareAll versions
SupermicroX11ddw-L FirmwareAll versions
SupermicroX11ddw-Nt FirmwareAll versions
SupermicroX11dgo-T FirmwareAll versions
SupermicroX11dgq FirmwareAll versions
SupermicroX11dpff-Sn FirmwareAll versions
SupermicroX11dpfr-S FirmwareAll versions
SupermicroX11dpfr-Sn FirmwareAll versions
SupermicroX11dpg-Ot-Cpu FirmwareAll versions
SupermicroX11dpg-Qt FirmwareAll versions
SupermicroX11dpg-Sn FirmwareAll versions
SupermicroX11dph-I FirmwareAll versions
SupermicroX11dph-T FirmwareAll versions
SupermicroX11dph-Tq FirmwareAll versions
SupermicroX11dpi-N FirmwareAll versions
SupermicroX11dpi-Nt FirmwareAll versions
SupermicroX11dpl-I FirmwareAll versions
SupermicroX11dps-Re FirmwareAll versions
SupermicroX11dpt-B FirmwareAll versions
SupermicroX11dpt-Bh FirmwareAll versions
SupermicroX11dpt-L FirmwareAll versions
SupermicroX11dpt-Ps FirmwareAll versions
SupermicroX11dpu FirmwareAll versions
SupermicroX11dpu-V FirmwareAll versions
SupermicroX11dpu-X FirmwareAll versions
SupermicroX11dpu-Xll FirmwareAll versions
SupermicroX11dpu-Z\+ FirmwareAll versions
SupermicroX11dpu-Ze\+ FirmwareAll versions
SupermicroX11dpx-T FirmwareAll versions
SupermicroX11dsc\+ FirmwareAll versions
SupermicroX11dsf-E FirmwareAll versions
SupermicroX11dsn-Ts FirmwareAll versions
SupermicroX11dsn-Tsq FirmwareAll versions
SupermicroX11opi-Cpu FirmwareAll versions
SupermicroX11qph\+ FirmwareAll versions
SupermicroX11sae FirmwareAll versions
SupermicroX11sae M FirmwareAll versions
SupermicroX11sat FirmwareAll versions
SupermicroX11sba FirmwareAll versions
SupermicroX11sca FirmwareAll versions
SupermicroX11sca-F FirmwareAll versions
SupermicroX11sca-W FirmwareAll versions
SupermicroX11scd-F FirmwareAll versions
SupermicroX11sch-F FirmwareAll versions
SupermicroX11sch-Ln4f FirmwareAll versions
SupermicroX11scl-F FirmwareAll versions
SupermicroX11scl-If FirmwareAll versions
SupermicroX11scl-Ln4f FirmwareAll versions

Showing 50 of 147 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2022-43309?
Supermicro X11SSL-CF HW Rev 1.01, BMC firmware v1.63 was discovered to contain insecure permissions.
How severe is CVE-2022-43309?
CVE-2022-43309 has a CVSS score of 5.5/10 (MEDIUM severity). The EPSS model estimates a 0.18% probability of exploitation in the next 30 days.
How do I fix CVE-2022-43309?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-43309?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST