← Back

Supermicro

supermicro

29 CVEs • 1,496 products

Products (1,496)

Click to collapse
Toggle

CVEs (29)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Supermicro
321A1sa2 2750f Firmware
A1sai 2550f FirmwareA1sai 2750f Firmware+318 more
Nov 21, 2024
Sep 21, 2019
N/A· v4
10.0 CRITICAL· v3
5.0 MEDIUM· v2
On Supermicro H11, H12, M11, X9, X10, and X11 products, a combination of encryption and authentication problems in the virtual media service allows capture of BMC credentials and data transferred over virtual media devic...Show more
On Supermicro H11, H12, M11, X9, X10, and X11 products, a combination of encryption and authentication problems in the virtual media service allows capture of BMC credentials and data transferred over virtual media devices. Attackers can use captured credentials to connect virtual USB devices to the server managed by the BMC.Show less
1Supermicro
1Superdoctor 5
Nov 21, 2024
Jul 1, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Super Micro SuperDoctor 5, when restrictions are not implemented in agent.cfg, allows remote attackers to execute arbitrary commands via NRPE.
1Supermicro
110A1sa Firmware
A1sai1 FirmwareA1sai Firmware+107 more
Nov 21, 2024
Jul 9, 2018
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
Certain Supermicro X11S, X10, X9, X8SI, K1SP, C9X299, C7, B1, A2, and A1 products have a misconfigured Descriptor Region, allowing OS programs to modify firmware.
1Supermicro
1Intelligent Platform Management Firmware
Apr 29, 2026
Dec 10, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple stack-based buffer overflows in cgi/close_window.cgi in the web interface in the Intelligent Platform Management Interface (IPMI) with firmware before 3.15 (SMT_X9_315) on Supermicro X9 generation motherboards a...Show more
Multiple stack-based buffer overflows in cgi/close_window.cgi in the web interface in the Intelligent Platform Management Interface (IPMI) with firmware before 3.15 (SMT_X9_315) on Supermicro X9 generation motherboards allow remote attackers to execute arbitrary code via the (1) sess_sid or (2) ACT parameter.Show less
1Supermicro
1Intelligent Platform Management Firmware
Apr 29, 2026
Dec 10, 2013
N/A· v4
N/A· v3
9.0 HIGH· v2
Buffer overflow in logout.cgi in the Intelligent Platform Management Interface (IPMI) with firmware before 3.15 (SMT_X9_315) on Supermicro X9 generation motherboards allows remote authenticated users to execute arbitrary...Show more
Buffer overflow in logout.cgi in the Intelligent Platform Management Interface (IPMI) with firmware before 3.15 (SMT_X9_315) on Supermicro X9 generation motherboards allows remote authenticated users to execute arbitrary code via the SID parameter.Show less
1Supermicro
126H8dcl 6f
H8dcl IfH8dct Hibqf+123 more
Apr 29, 2026
Sep 8, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
The web interface in the Intelligent Platform Management Interface (IPMI) implementation on Supermicro H8DC*, H8DG*, H8SCM-F, H8SGL-F, H8SM*, X7SP*, X8DT*, X8SI*, X9DAX-*, X9DB*, X9DR*, X9QR*, X9SBAA-F, X9SC*, X9SPU-F, a...Show more
The web interface in the Intelligent Platform Management Interface (IPMI) implementation on Supermicro H8DC*, H8DG*, H8SCM-F, H8SGL-F, H8SM*, X7SP*, X8DT*, X8SI*, X9DAX-*, X9DB*, X9DR*, X9QR*, X9SBAA-F, X9SC*, X9SPU-F, and X9SR* devices relies on JavaScript code on the client for authorization checks, which allows remote authenticated users to bypass intended access restrictions via a crafted request, related to the PrivilegeCallBack function.Show less
1Supermicro
126H8dcl 6f
H8dcl IfH8dct Hibqf+123 more
Apr 29, 2026
Sep 8, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
The web interface in the Intelligent Platform Management Interface (IPMI) implementation on Supermicro H8DC*, H8DG*, H8SCM-F, H8SGL-F, H8SM*, X7SP*, X8DT*, X8SI*, X9DAX-*, X9DB*, X9DR*, X9QR*, X9SBAA-F, X9SC*, X9SPU-F, a...Show more
The web interface in the Intelligent Platform Management Interface (IPMI) implementation on Supermicro H8DC*, H8DG*, H8SCM-F, H8SGL-F, H8SM*, X7SP*, X8DT*, X8SI*, X9DAX-*, X9DB*, X9DR*, X9QR*, X9SBAA-F, X9SC*, X9SPU-F, and X9SR* devices allows remote authenticated users to execute arbitrary commands via shell metacharacters, as demonstrated by the IP address field in config_date_time.cgi.Show less
1Supermicro
126H8dcl 6f
H8dcl IfH8dct Hibqf+123 more
Apr 29, 2026
Sep 8, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple stack-based buffer overflows in the web interface in the Intelligent Platform Management Interface (IPMI) implementation on Supermicro H8DC*, H8DG*, H8SCM-F, H8SGL-F, H8SM*, X7SP*, X8DT*, X8SI*, X9DAX-*, X9DB*,...Show more
Multiple stack-based buffer overflows in the web interface in the Intelligent Platform Management Interface (IPMI) implementation on Supermicro H8DC*, H8DG*, H8SCM-F, H8SGL-F, H8SM*, X7SP*, X8DT*, X8SI*, X9DAX-*, X9DB*, X9DR*, X9QR*, X9SBAA-F, X9SC*, X9SPU-F, and X9SR* devices allow remote attackers to execute arbitrary code on the Baseboard Management Controller (BMC), as demonstrated by the (1) username or (2) password field in login.cgi.Show less
1Supermicro
1Bmc
Apr 29, 2026
Jul 8, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
The Supermicro BMC implementation allows remote attackers to bypass authentication and execute arbitrary IPMI commands by using cipher suite 0 (aka cipher zero) and an arbitrary password.