CVE-2023-35861
Last modified
CVE-2023-35861 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A shell-injection vulnerability in email notifications on Supermicro motherboards (such as H12DST-B before 03.10.35) allows remote attackers to inject execute arbitrary commands as root on the BMC.. EPSS estimates a 1.54% chance of exploitation in the next 30 days.
Description
A shell-injection vulnerability in email notifications on Supermicro motherboards (such as H12DST-B before 03.10.35) allows remote attackers to inject execute arbitrary commands as root on the BMC.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Supermicro | H12dst-B Firmware | < 03.10.35 |
| Supermicro | X13dai-T Firmware | All versions |
| Supermicro | X13ddw-A Firmware | All versions |
| Supermicro | X13deg-Oa Firmware | All versions |
| Supermicro | X13deg-Oad Firmware | All versions |
| Supermicro | X13deg-Pvc Firmware | All versions |
| Supermicro | X13deg-Qt Firmware | All versions |
| Supermicro | X13dei Firmware | All versions |
| Supermicro | X13dei-T Firmware | All versions |
| Supermicro | X13dem Firmware | All versions |
| Supermicro | X13det-B Firmware | All versions |
| Supermicro | X13dgu Firmware | All versions |
| Supermicro | X13dsf-A Firmware | All versions |
| Supermicro | X13qeh\+ Firmware | All versions |
| Supermicro | X13sae Firmware | All versions |
| Supermicro | X13sae-F Firmware | All versions |
| Supermicro | X13san-C Firmware | All versions |
| Supermicro | X13san-C-Wohs Firmware | All versions |
| Supermicro | X13san-E Firmware | All versions |
| Supermicro | X13san-E-Wohs Firmware | All versions |
| Supermicro | X13san-H Firmware | All versions |
| Supermicro | X13san-H-Wohs Firmware | All versions |
| Supermicro | X13san-L Firmware | All versions |
| Supermicro | X13san-L-Wohs Firmware | All versions |
| Supermicro | X13saq Firmware | All versions |
| Supermicro | X13sav-Lvds Firmware | All versions |
| Supermicro | X13sav-Ps Firmware | All versions |
| Supermicro | X13saz-F Firmware | All versions |
| Supermicro | X13saz-Q Firmware | All versions |
| Supermicro | X13sedw-F Firmware | All versions |
| Supermicro | X13seed-F Firmware | All versions |
| Supermicro | X13seed-Sf Firmware | All versions |
| Supermicro | X13sefr-A Firmware | All versions |
| Supermicro | X13sei-F Firmware | All versions |
| Supermicro | X13sei-Tf Firmware | All versions |
| Supermicro | X13sem-F Firmware | All versions |
| Supermicro | X13sem-Tf Firmware | All versions |
| Supermicro | X13set-G Firmware | All versions |
| Supermicro | X13set-Gc Firmware | All versions |
| Supermicro | X13sew-F Firmware | All versions |
| Supermicro | X13sew-Tf Firmware | All versions |
| Supermicro | X13sra-Tf Firmware | All versions |
| Supermicro | X13srn-E Firmware | All versions |
| Supermicro | X13srn-E-Wohs Firmware | All versions |
| Supermicro | X13srn-H Firmware | All versions |
| Supermicro | X13srn-H-Wohs Firmware | All versions |
| Supermicro | X13swa-Tf Firmware | All versions |
| Supermicro | H13dsg-O-Cpu Firmware | All versions |
| Supermicro | H13dsg-O-Cpu-D Firmware | All versions |
| Supermicro | H13dsh Firmware | All versions |
Showing 50 of 166 affected configurations. See NVD for the full list.
References
- https://blog.freax13.de/cve/cve-2023-35861Exploit, Third Party Advisory
- https://www.supermicro.com/en/support/security_SMTP_Jun_2023Vendor Advisory
- https://blog.freax13.de/cve/cve-2023-35861Exploit, Third Party Advisory
- https://www.supermicro.com/en/support/security_SMTP_Jun_2023Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-35861?
How severe is CVE-2023-35861?
How do I fix CVE-2023-35861?
Are you affected by CVE-2023-35861?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
