Vulnerability Description
Directory traversal vulnerability in url_redirect.cgi in Supermicro IPMI before SMT_X9_315 allows authenticated attackers to read arbitrary files via the url_name parameter.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Supermicro | Intelligent Platform Management Interface | < smt_x9_315 |
Related Weaknesses (CWE)
References
- https://blog.rapid7.com/2013/11/06/supermicro-ipmi-firmware-vulnerabilities/Not Applicable
- https://www.tenable.com/cve/CVE-2013-6785Third Party Advisory
- https://blog.rapid7.com/2013/11/06/supermicro-ipmi-firmware-vulnerabilities/Not Applicable
FAQ
What is CVE-2013-6785?
CVE-2013-6785 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Directory traversal vulnerability in url_redirect.cgi in Supermicro IPMI before SMT_X9_315 allows authenticated attackers to read arbitrary files via the url_name parameter.
How severe is CVE-2013-6785?
CVE-2013-6785 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-6785?
Check the references section above for vendor advisories and patch information. Affected products include: Supermicro Intelligent Platform Management Interface.