Vulnerability Description
Buffer Overflow vulnerability in Supermicro motherboard X12DPG-QR 1.4b allows local attackers to hijack control flow via manipulation of SmcSecurityEraseSetupVar variable.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Supermicro | X12Dai-N6 Firmware | - |
| Supermicro | X12Dai-N6 | - |
| Supermicro | X12Ddw-A6 Firmware | - |
| Supermicro | X12Ddw-A6 | - |
| Supermicro | X12Dgo-6 Firmware | - |
| Supermicro | X12Dgo-6 | - |
| Supermicro | X12Dgq-R Firmware | - |
| Supermicro | X12Dgq-R | - |
| Supermicro | X12Dgu Firmware | - |
| Supermicro | X12Dgu | - |
| Supermicro | X12Dhm-6 Firmware | - |
| Supermicro | X12Dhm-6 | - |
| Supermicro | X12Dpd-A6M25 Firmware | - |
| Supermicro | X12Dpd-A6M25 | - |
| Supermicro | X12Dpfr-An6 Firmware | - |
| Supermicro | X12Dpfr-An6 | - |
| Supermicro | X12Dpg-Ar Firmware | - |
| Supermicro | X12Dpg-Ar | - |
| Supermicro | X12Dpg-Oa6 Firmware | - |
| Supermicro | X12Dpg-Oa6 | - |
Related Weaknesses (CWE)
References
- https://www.supermicro.com/Bios/softfiles/17136/X12DPG-QR_1.4b_X1.02.61_SUM2.10.Product
- https://www.supermicro.com/en/support/security_BIOS_Aug_2023Vendor Advisory
- https://www.supermicro.com/Bios/softfiles/17136/X12DPG-QR_1.4b_X1.02.61_SUM2.10.Product
- https://www.supermicro.com/en/support/security_BIOS_Aug_2023Vendor Advisory
FAQ
What is CVE-2023-34853?
CVE-2023-34853 is a vulnerability with a CVSS score of 7.8 (HIGH). Buffer Overflow vulnerability in Supermicro motherboard X12DPG-QR 1.4b allows local attackers to hijack control flow via manipulation of SmcSecurityEraseSetupVar variable.
How severe is CVE-2023-34853?
CVE-2023-34853 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-34853?
Check the references section above for vendor advisories and patch information. Affected products include: Supermicro X12Dai-N6 Firmware, Supermicro X12Dai-N6, Supermicro X12Ddw-A6 Firmware, Supermicro X12Ddw-A6, Supermicro X12Dgo-6 Firmware.