HIGH · 10.0

CVE-2013-3608

The web interface in the Intelligent Platform Management Interface (IPMI) implementation on Supermicro H8DC*, H8DG*, H8SCM-F, H8SGL-F, H8SM*, X7SP*, X8DT*, X8SI*, X9DAX-*, X9DB*, X9DR*, X9QR*, X9SBAA-...

Vulnerability Description

The web interface in the Intelligent Platform Management Interface (IPMI) implementation on Supermicro H8DC*, H8DG*, H8SCM-F, H8SGL-F, H8SM*, X7SP*, X8DT*, X8SI*, X9DAX-*, X9DB*, X9DR*, X9QR*, X9SBAA-F, X9SC*, X9SPU-F, and X9SR* devices allows remote authenticated users to execute arbitrary commands via shell metacharacters, as demonstrated by the IP address field in config_date_time.cgi.

CVSS Score

10.0

HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
SupermicroH8Dcl-6F-
SupermicroH8Dcl-If-
SupermicroH8Dct-Hibqf-
SupermicroH8Dct-Hln4F-
SupermicroH8Dct-Ibqf-
SupermicroH8Dg6-F-
SupermicroH8Dgg-Qf-
SupermicroH8Dgi-F-
SupermicroH8Dgt-Hf-
SupermicroH8Dgt-Hibqf-
SupermicroH8Dgt-Hlf-
SupermicroH8Dgt-Hlibqf-
SupermicroH8Dgu-F-
SupermicroH8Dgu-Ln4F\+-
SupermicroH8Scm-F-
SupermicroH8Sgl-F-
SupermicroH8Sme-F-
SupermicroH8Sml-7-
SupermicroH8Sml-7F-
SupermicroH8Sml-I-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2013-3608?

CVE-2013-3608 is a vulnerability with a CVSS score of 10.0 (HIGH). The web interface in the Intelligent Platform Management Interface (IPMI) implementation on Supermicro H8DC*, H8DG*, H8SCM-F, H8SGL-F, H8SM*, X7SP*, X8DT*, X8SI*, X9DAX-*, X9DB*, X9DR*, X9QR*, X9SBAA-...

How severe is CVE-2013-3608?

CVE-2013-3608 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2013-3608?

Check the references section above for vendor advisories and patch information. Affected products include: Supermicro H8Dcl-6F, Supermicro H8Dcl-If, Supermicro H8Dct-Hibqf, Supermicro H8Dct-Hln4F, Supermicro H8Dct-Ibqf.