CVE-2013-3607
10.0
Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 10.0 / Impact: 10.0
Source: NVD
Description
Multiple stack-based buffer overflows in the web interface in the Intelligent Platform Management Interface (IPMI) implementation on Supermicro H8DC*, H8DG*, H8SCM-F, H8SGL-F, H8SM*, X7SP*, X8DT*, X8SI*, X9DAX-*, X9DB*, X9DR*, X9QR*, X9SBAA-F, X9SC*, X9SPU-F, and X9SR* devices allow remote attackers to execute arbitrary code on the Baseboard Management Controller (BMC), as demonstrated by the (1) username or (2) password field in login.cgi.
Affected (133)
Products: Supermicro: H8dcl 6f, H8dcl If, H8dct Hibqf, H8dct Hln4f, H8dct Ibqf, H8dg6 F, H8dgg Qf, H8dgi F, H8dgt Hf, H8dgt Hibqf, H8dgt Hlf, H8dgt Hlibqf, H8dgu F, H8dgu Ln4f+, H8scm F, H8sgl F, H8sme F, H8sml 7, H8sml 7f, H8sml I, H8sml If, X7spa Hf, X7spa Hf D525, X7spe H D525, X7spe Hf, X7spe Hf D525, X7spt Df D525+, X8dtl 3f, X8dtl 6f, X8dtl If, X8dtn+ F, X8dtn+ F Lr, X8dtu 6f+, X8dtu 6f+ Lr, X8dtu 6tf+, X8dtu 6tf+ Lr, X8dtu Ln4f+, X8dtu Ln4f+ Lr, X8si6 F, X8sia F, X8sie F, X8sie Ln4f, X8sil F, X8sit F, X8sit Hf, X8siu F, X9dax 7f, X9dax 7f Hft, X9dax 7tf, X9dax If, X9dax If Hft, X9dax Itf, X9db3 F, X9db3 Tpf, X9dbi F, X9dbi Tpf, X9dbl 3f, X9dbl If, X9dbu 3f, X9dbu If, X9dr3 F, X9dr3 Ln4f+, X9dr7 Ln4f, X9dr7 Ln4f Jbod, X9dr7 Tf+, X9drd 7jln4f, X9drd 7ln4f, X9drd 7ln4f Jbod, X9drd Ef, X9drd If, X9dre Ln4f, X9dre Tf+, X9drff, X9drff 7+, X9drff 7g+, X9drff 7t+, X9drff 7tg+, X9drff I+, X9drff Ig+, X9drff It+, X9drff Itg+, X9drfr, X9drg Hf+, X9drg Htf+, X9drh 7f, X9drh 7tf, X9drh If, X9drh Itf, X9dri F, X9dri Ln4f+, X9drl 3f, X9drl Ef, X9drl If, X9drt F, X9drt H6f, X9drt H6ibff, X9drt H6ibqf, X9drt Hf+, X9drt Ibff, X9drt Ibqf, X9drw 3ln4f+, X9drw 3tf+, X9drw 7tpf+, X9drw Itpf+, X9drx+ F, X9qr7 Tf+, X9qr7 Tf Jbod, X9qri F+, X9sbaa F, X9sca F, X9scd F, X9sce F, X9scff F, X9sci Ln4f, X9scl F, X9scm F, X9scm Iif, X9spu F, X9srd F, X9sre 3f, X9sre F, X9srg F, X9sri 3f, X9sri F, X9srl F, X9srw F
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions |
References (12)
Source: cret@cert.org
Source: cret@cert.org
Source: cret@cert.org
Source: cret@cert.org
Source: cret@cert.org
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Timeline
No history available yet.