Vulnerability Description
A shell-injection vulnerability in email notifications on Supermicro motherboards (such as H12DST-B before 03.10.35) allows remote attackers to inject execute arbitrary commands as root on the BMC.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Supermicro | H12Dst-B Firmware | < 03.10.35 |
| Supermicro | H12Dst-B | - |
| Supermicro | X13Dai-T Firmware | - |
| Supermicro | X13Dai-T | - |
| Supermicro | X13Ddw-A Firmware | - |
| Supermicro | X13Ddw-A | - |
| Supermicro | X13Deg-Oa Firmware | - |
| Supermicro | X13Deg-Oa | - |
| Supermicro | X13Deg-Oad Firmware | - |
| Supermicro | X13Deg-Oad | - |
| Supermicro | X13Deg-Pvc Firmware | - |
| Supermicro | X13Deg-Pvc | - |
| Supermicro | X13Deg-Qt Firmware | - |
| Supermicro | X13Deg-Qt | - |
| Supermicro | X13Dei Firmware | - |
| Supermicro | X13Dei | - |
| Supermicro | X13Dei-T Firmware | - |
| Supermicro | X13Dei-T | - |
| Supermicro | X13Dem Firmware | - |
| Supermicro | X13Dem | - |
Related Weaknesses (CWE)
References
- https://blog.freax13.de/cve/cve-2023-35861ExploitThird Party Advisory
- https://www.supermicro.com/en/products/motherboardsProduct
- https://www.supermicro.com/en/support/security_SMTP_Jun_2023Vendor Advisory
- https://blog.freax13.de/cve/cve-2023-35861ExploitThird Party Advisory
- https://www.supermicro.com/en/products/motherboardsProduct
- https://www.supermicro.com/en/support/security_SMTP_Jun_2023Vendor Advisory
FAQ
What is CVE-2023-35861?
CVE-2023-35861 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A shell-injection vulnerability in email notifications on Supermicro motherboards (such as H12DST-B before 03.10.35) allows remote attackers to inject execute arbitrary commands as root on the BMC.
How severe is CVE-2023-35861?
CVE-2023-35861 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-35861?
Check the references section above for vendor advisories and patch information. Affected products include: Supermicro H12Dst-B Firmware, Supermicro H12Dst-B, Supermicro X13Dai-T Firmware, Supermicro X13Dai-T, Supermicro X13Ddw-A Firmware.