HIGH · 10.0

CVE-2013-3609

The web interface in the Intelligent Platform Management Interface (IPMI) implementation on Supermicro H8DC*, H8DG*, H8SCM-F, H8SGL-F, H8SM*, X7SP*, X8DT*, X8SI*, X9DAX-*, X9DB*, X9DR*, X9QR*, X9SBAA-...

Vulnerability Description

The web interface in the Intelligent Platform Management Interface (IPMI) implementation on Supermicro H8DC*, H8DG*, H8SCM-F, H8SGL-F, H8SM*, X7SP*, X8DT*, X8SI*, X9DAX-*, X9DB*, X9DR*, X9QR*, X9SBAA-F, X9SC*, X9SPU-F, and X9SR* devices relies on JavaScript code on the client for authorization checks, which allows remote authenticated users to bypass intended access restrictions via a crafted request, related to the PrivilegeCallBack function.

CVSS Score

10.0

HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
SupermicroH8Dcl-6F-
SupermicroH8Dcl-If-
SupermicroH8Dct-Hibqf-
SupermicroH8Dct-Hln4F-
SupermicroH8Dct-Ibqf-
SupermicroH8Dg6-F-
SupermicroH8Dgg-Qf-
SupermicroH8Dgi-F-
SupermicroH8Dgt-Hf-
SupermicroH8Dgt-Hibqf-
SupermicroH8Dgt-Hlf-
SupermicroH8Dgt-Hlibqf-
SupermicroH8Dgu-F-
SupermicroH8Dgu-Ln4F\+-
SupermicroH8Scm-F-
SupermicroH8Sgl-F-
SupermicroH8Sme-F-
SupermicroH8Sml-7-
SupermicroH8Sml-7F-
SupermicroH8Sml-I-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2013-3609?

CVE-2013-3609 is a vulnerability with a CVSS score of 10.0 (HIGH). The web interface in the Intelligent Platform Management Interface (IPMI) implementation on Supermicro H8DC*, H8DG*, H8SCM-F, H8SGL-F, H8SM*, X7SP*, X8DT*, X8SI*, X9DAX-*, X9DB*, X9DR*, X9QR*, X9SBAA-...

How severe is CVE-2013-3609?

CVE-2013-3609 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2013-3609?

Check the references section above for vendor advisories and patch information. Affected products include: Supermicro H8Dcl-6F, Supermicro H8Dcl-If, Supermicro H8Dct-Hibqf, Supermicro H8Dct-Hln4F, Supermicro H8Dct-Ibqf.