The web interface in the Intelligent Platform Management Interface (IPMI) implementation on Supermicro H8DC*, H8DG*, H8SCM-F, H8SGL-F, H8SM*, X7SP*, X8DT*, X8SI*, X9DAX-*, X9DB*, X9DR*, X9QR*, X9SBAA-F, X9SC*, X9SPU-F, and X9SR* devices relies on JavaScript code on the client for authorization checks, which allows remote authenticated users to bypass intended access restrictions via a crafted request, related to the PrivilegeCallBack function.

Project Subscriptions

Vendors Products
Supermicro Subscribe
H8dcl-6f Subscribe
H8dcl-if Subscribe
H8dct-hibqf Subscribe
H8dct-hln4f Subscribe
H8dct-ibqf Subscribe
H8dg6-f Subscribe
H8dgg-qf Subscribe
H8dgi-f Subscribe
H8dgt-hf Subscribe
H8dgt-hibqf Subscribe
H8dgt-hlf Subscribe
H8dgt-hlibqf Subscribe
H8dgu-f Subscribe
H8dgu-ln4f\+ Subscribe
H8scm-f Subscribe
H8sgl-f Subscribe
H8sme-f Subscribe
H8sml-7 Subscribe
H8sml-7f Subscribe
H8sml-i Subscribe
H8sml-if Subscribe
X7spa-hf Subscribe
X7spa-hf-d525 Subscribe
X7spe-h-d525 Subscribe
X7spe-hf Subscribe
X7spe-hf-d525 Subscribe
X7spt-df-d525 Subscribe
X7spt-df-d525\+ Subscribe
X8dtl-3f Subscribe
X8dtl-6f Subscribe
X8dtl-if Subscribe
X8dtn\+-f Subscribe
X8dtn\+-f-lr Subscribe
X8dtu-6f\+ Subscribe
X8dtu-6f\+-lr Subscribe
X8dtu-6tf\+ Subscribe
X8dtu-6tf\+-lr Subscribe
X8dtu-ln4f\+ Subscribe
X8dtu-ln4f\+-lr Subscribe
X8si6-f Subscribe
X8sia-f Subscribe
X8sie-f Subscribe
X8sie-ln4f Subscribe
X8sil-f Subscribe
X8sit-f Subscribe
X8sit-hf Subscribe
X8siu-f Subscribe
X9dax-7f Subscribe
X9dax-7f-hft Subscribe
X9dax-7tf Subscribe
X9dax-if Subscribe
X9dax-if-hft Subscribe
X9dax-itf Subscribe
X9db3-f Subscribe
X9db3-tpf Subscribe
X9dbi-f Subscribe
X9dbi-tpf Subscribe
X9dbl-3f Subscribe
X9dbl-if Subscribe
X9dbu-3f Subscribe
X9dbu-if Subscribe
X9dr3-f Subscribe
X9dr3-ln4f\+ Subscribe
X9dr7-ln4f Subscribe
X9dr7-ln4f-jbod Subscribe
X9dr7-tf\+ Subscribe
X9drd-7jln4f Subscribe
X9drd-7ln4f Subscribe
X9drd-7ln4f-jbod Subscribe
X9drd-ef Subscribe
X9drd-if Subscribe
X9dre-ln4f Subscribe
X9dre-tf\+ Subscribe
X9drff-7 Subscribe
X9drff-7\+ Subscribe
X9drff-7g\+ Subscribe
X9drff-7t\+ Subscribe
X9drff-7tg\+ Subscribe
X9drff-i\+ Subscribe
X9drff-ig\+ Subscribe
X9drff-it\+ Subscribe
X9drff-itg\+ Subscribe
X9drg-hf Subscribe
X9drg-hf\+ Subscribe
X9drg-htf Subscribe
X9drg-htf\+ Subscribe
X9drh-7f Subscribe
X9drh-7tf Subscribe
X9drh-if Subscribe
X9drh-itf Subscribe
X9dri-f Subscribe
X9dri-ln4f\+ Subscribe
X9drl-3f Subscribe
X9drl-ef Subscribe
X9drl-if Subscribe
X9drt-f Subscribe
X9drt-h6f Subscribe
X9drt-h6ibff Subscribe
X9drt-h6ibqf Subscribe
X9drt-hf\+ Subscribe
X9drt-ibff Subscribe
X9drt-ibqf Subscribe
X9drw-3ln4f\+ Subscribe
X9drw-3tf\+ Subscribe
X9drw-7tpf\+ Subscribe
X9drw-itpf\+ Subscribe
X9drx\+-f Subscribe
X9qr7-tf Subscribe
X9qr7-tf-jbod Subscribe
X9qr7-tf\+ Subscribe
X9qri-f Subscribe
X9qri-f\+ Subscribe
X9sbaa-f Subscribe
X9sca-f Subscribe
X9scd-f Subscribe
X9sce-f Subscribe
X9scff-f Subscribe
X9sci-ln4f Subscribe
X9scl-f Subscribe
X9scl\+-f Subscribe
X9scm-f Subscribe
X9scm-iif Subscribe
X9spu-f Subscribe
X9srd-f Subscribe
X9sre-3f Subscribe
X9sre-f Subscribe
X9srg-f Subscribe
X9sri-3f Subscribe
X9sri-f Subscribe
X9srl-f Subscribe
X9srw-f Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2013-3543 The web interface in the Intelligent Platform Management Interface (IPMI) implementation on Supermicro H8DC*, H8DG*, H8SCM-F, H8SGL-F, H8SM*, X7SP*, X8DT*, X8SI*, X9DAX-*, X9DB*, X9DR*, X9QR*, X9SBAA-F, X9SC*, X9SPU-F, and X9SR* devices relies on JavaScript code on the client for authorization checks, which allows remote authenticated users to bypass intended access restrictions via a crafted request, related to the PrivilegeCallBack function.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2024-08-06T16:14:56.568Z

Reserved: 2013-05-21T00:00:00.000Z

Link: CVE-2013-3609

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2013-09-08T03:17:39.603

Modified: 2025-04-11T00:51:21.963

Link: CVE-2013-3609

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses