Vulnerability Description
Certain Supermicro X11S, X10, X9, X8SI, K1SP, C9X299, C7, B1, A2, and A1 products have a misconfigured Descriptor Region, allowing OS programs to modify firmware.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Supermicro | X11Ssz Firmware | - |
| Supermicro | X11Ssz | - |
| Supermicro | X11Ssv Firmware | - |
| Supermicro | X11Ssv | - |
| Supermicro | X11Ssql Firmware | - |
| Supermicro | X11Ssql | - |
| Supermicro | X11Ssq Firmware | - |
| Supermicro | X11Ssq | - |
| Supermicro | X11Ssn Firmware | - |
| Supermicro | X11Ssn | - |
| Supermicro | X11Srm Firmware | - |
| Supermicro | X11Srm | - |
| Supermicro | X11Sra Firmware | - |
| Supermicro | X11Sra | - |
| Supermicro | X11Sba Firmware | - |
| Supermicro | X11Sba | - |
| Supermicro | X11Sat Firmware | - |
| Supermicro | X11Sat | - |
| Supermicro | X11Sae M Firmware | - |
| Supermicro | X11Sae M | - |
References
- https://blog.eclypsium.com/2018/06/07/firmware-vulnerabilities-in-supermicro-sysThird Party Advisory
- https://www.bleepingcomputer.com/news/security/firmware-vulnerabilities-discloseThird Party Advisory
- https://www.supermicro.com/support/security_Intel-SA-00088.cfm?pg=X10#tabThird Party Advisory
- https://blog.eclypsium.com/2018/06/07/firmware-vulnerabilities-in-supermicro-sysThird Party Advisory
- https://www.bleepingcomputer.com/news/security/firmware-vulnerabilities-discloseThird Party Advisory
- https://www.supermicro.com/support/security_Intel-SA-00088.cfm?pg=X10#tabThird Party Advisory
FAQ
What is CVE-2018-13787?
CVE-2018-13787 is a vulnerability with a CVSS score of 6.7 (MEDIUM). Certain Supermicro X11S, X10, X9, X8SI, K1SP, C9X299, C7, B1, A2, and A1 products have a misconfigured Descriptor Region, allowing OS programs to modify firmware.
How severe is CVE-2018-13787?
CVE-2018-13787 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-13787?
Check the references section above for vendor advisories and patch information. Affected products include: Supermicro X11Ssz Firmware, Supermicro X11Ssz, Supermicro X11Ssv Firmware, Supermicro X11Ssv, Supermicro X11Ssql Firmware.