The web interface in the Intelligent Platform Management Interface (IPMI) implementation on Supermicro H8DC*, H8DG*, H8SCM-F, H8SGL-F, H8SM*, X7SP*, X8DT*, X8SI*, X9DAX-*, X9DB*, X9DR*, X9QR*, X9SBAA-F, X9SC*, X9SPU-F, and X9SR* devices allows remote authenticated users to execute arbitrary commands via shell metacharacters, as demonstrated by the IP address field in config_date_time.cgi.

Project Subscriptions

Vendors Products
Supermicro Subscribe
H8dcl-6f Subscribe
H8dcl-if Subscribe
H8dct-hibqf Subscribe
H8dct-hln4f Subscribe
H8dct-ibqf Subscribe
H8dg6-f Subscribe
H8dgg-qf Subscribe
H8dgi-f Subscribe
H8dgt-hf Subscribe
H8dgt-hibqf Subscribe
H8dgt-hlf Subscribe
H8dgt-hlibqf Subscribe
H8dgu-f Subscribe
H8dgu-ln4f\+ Subscribe
H8scm-f Subscribe
H8sgl-f Subscribe
H8sme-f Subscribe
H8sml-7 Subscribe
H8sml-7f Subscribe
H8sml-i Subscribe
H8sml-if Subscribe
X7spa-hf Subscribe
X7spa-hf-d525 Subscribe
X7spe-h-d525 Subscribe
X7spe-hf Subscribe
X7spe-hf-d525 Subscribe
X7spt-df-d525 Subscribe
X7spt-df-d525\+ Subscribe
X8dtl-3f Subscribe
X8dtl-6f Subscribe
X8dtl-if Subscribe
X8dtn\+-f Subscribe
X8dtn\+-f-lr Subscribe
X8dtu-6f\+ Subscribe
X8dtu-6f\+-lr Subscribe
X8dtu-6tf\+ Subscribe
X8dtu-6tf\+-lr Subscribe
X8dtu-ln4f\+ Subscribe
X8dtu-ln4f\+-lr Subscribe
X8si6-f Subscribe
X8sia-f Subscribe
X8sie-f Subscribe
X8sie-ln4f Subscribe
X8sil-f Subscribe
X8sit-f Subscribe
X8sit-hf Subscribe
X8siu-f Subscribe
X9dax-7f Subscribe
X9dax-7f-hft Subscribe
X9dax-7tf Subscribe
X9dax-if Subscribe
X9dax-if-hft Subscribe
X9dax-itf Subscribe
X9db3-f Subscribe
X9db3-tpf Subscribe
X9dbi-f Subscribe
X9dbi-tpf Subscribe
X9dbl-3f Subscribe
X9dbl-if Subscribe
X9dbu-3f Subscribe
X9dbu-if Subscribe
X9dr3-f Subscribe
X9dr3-ln4f\+ Subscribe
X9dr7-ln4f Subscribe
X9dr7-ln4f-jbod Subscribe
X9dr7-tf\+ Subscribe
X9drd-7jln4f Subscribe
X9drd-7ln4f Subscribe
X9drd-7ln4f-jbod Subscribe
X9drd-ef Subscribe
X9drd-if Subscribe
X9dre-ln4f Subscribe
X9dre-tf\+ Subscribe
X9drff-7 Subscribe
X9drff-7\+ Subscribe
X9drff-7g\+ Subscribe
X9drff-7t\+ Subscribe
X9drff-7tg\+ Subscribe
X9drff-i\+ Subscribe
X9drff-ig\+ Subscribe
X9drff-it\+ Subscribe
X9drff-itg\+ Subscribe
X9drg-hf Subscribe
X9drg-hf\+ Subscribe
X9drg-htf Subscribe
X9drg-htf\+ Subscribe
X9drh-7f Subscribe
X9drh-7tf Subscribe
X9drh-if Subscribe
X9drh-itf Subscribe
X9dri-f Subscribe
X9dri-ln4f\+ Subscribe
X9drl-3f Subscribe
X9drl-ef Subscribe
X9drl-if Subscribe
X9drt-f Subscribe
X9drt-h6f Subscribe
X9drt-h6ibff Subscribe
X9drt-h6ibqf Subscribe
X9drt-hf\+ Subscribe
X9drt-ibff Subscribe
X9drt-ibqf Subscribe
X9drw-3ln4f\+ Subscribe
X9drw-3tf\+ Subscribe
X9drw-7tpf\+ Subscribe
X9drw-itpf\+ Subscribe
X9drx\+-f Subscribe
X9qr7-tf Subscribe
X9qr7-tf-jbod Subscribe
X9qr7-tf\+ Subscribe
X9qri-f Subscribe
X9qri-f\+ Subscribe
X9sbaa-f Subscribe
X9sca-f Subscribe
X9scd-f Subscribe
X9sce-f Subscribe
X9scff-f Subscribe
X9sci-ln4f Subscribe
X9scl-f Subscribe
X9scl\+-f Subscribe
X9scm-f Subscribe
X9scm-iif Subscribe
X9spu-f Subscribe
X9srd-f Subscribe
X9sre-3f Subscribe
X9sre-f Subscribe
X9srg-f Subscribe
X9sri-3f Subscribe
X9sri-f Subscribe
X9srl-f Subscribe
X9srw-f Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2013-3542 The web interface in the Intelligent Platform Management Interface (IPMI) implementation on Supermicro H8DC*, H8DG*, H8SCM-F, H8SGL-F, H8SM*, X7SP*, X8DT*, X8SI*, X9DAX-*, X9DB*, X9DR*, X9QR*, X9SBAA-F, X9SC*, X9SPU-F, and X9SR* devices allows remote authenticated users to execute arbitrary commands via shell metacharacters, as demonstrated by the IP address field in config_date_time.cgi.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2024-08-06T16:14:56.542Z

Reserved: 2013-05-21T00:00:00.000Z

Link: CVE-2013-3608

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2013-09-08T03:17:39.587

Modified: 2025-04-11T00:51:21.963

Link: CVE-2013-3608

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses