The web interface in the Intelligent Platform Management Interface (IPMI) implementation on Supermicro H8DC*, H8DG*, H8SCM-F, H8SGL-F, H8SM*, X7SP*, X8DT*, X8SI*, X9DAX-*, X9DB*, X9DR*, X9QR*, X9SBAA-F, X9SC*, X9SPU-F, and X9SR* devices relies on JavaScript code on the client for authorization checks, which allows remote authenticated users to bypass intended access restrictions via a crafted request, related to the PrivilegeCallBack function.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Supermicro
Subscribe
|
H8dcl-6f
Subscribe
H8dcl-if
Subscribe
H8dct-hibqf
Subscribe
H8dct-hln4f
Subscribe
H8dct-ibqf
Subscribe
H8dg6-f
Subscribe
H8dgg-qf
Subscribe
H8dgi-f
Subscribe
H8dgt-hf
Subscribe
H8dgt-hibqf
Subscribe
H8dgt-hlf
Subscribe
H8dgt-hlibqf
Subscribe
H8dgu-f
Subscribe
H8dgu-ln4f\+
Subscribe
H8scm-f
Subscribe
H8sgl-f
Subscribe
H8sme-f
Subscribe
H8sml-7
Subscribe
H8sml-7f
Subscribe
H8sml-i
Subscribe
H8sml-if
Subscribe
X7spa-hf
Subscribe
X7spa-hf-d525
Subscribe
X7spe-h-d525
Subscribe
X7spe-hf
Subscribe
X7spe-hf-d525
Subscribe
X7spt-df-d525
Subscribe
X7spt-df-d525\+
Subscribe
X8dtl-3f
Subscribe
X8dtl-6f
Subscribe
X8dtl-if
Subscribe
X8dtn\+-f
Subscribe
X8dtn\+-f-lr
Subscribe
X8dtu-6f\+
Subscribe
X8dtu-6f\+-lr
Subscribe
X8dtu-6tf\+
Subscribe
X8dtu-6tf\+-lr
Subscribe
X8dtu-ln4f\+
Subscribe
X8dtu-ln4f\+-lr
Subscribe
X8si6-f
Subscribe
X8sia-f
Subscribe
X8sie-f
Subscribe
X8sie-ln4f
Subscribe
X8sil-f
Subscribe
X8sit-f
Subscribe
X8sit-hf
Subscribe
X8siu-f
Subscribe
X9dax-7f
Subscribe
X9dax-7f-hft
Subscribe
X9dax-7tf
Subscribe
X9dax-if
Subscribe
X9dax-if-hft
Subscribe
X9dax-itf
Subscribe
X9db3-f
Subscribe
X9db3-tpf
Subscribe
X9dbi-f
Subscribe
X9dbi-tpf
Subscribe
X9dbl-3f
Subscribe
X9dbl-if
Subscribe
X9dbu-3f
Subscribe
X9dbu-if
Subscribe
X9dr3-f
Subscribe
X9dr3-ln4f\+
Subscribe
X9dr7-ln4f
Subscribe
X9dr7-ln4f-jbod
Subscribe
X9dr7-tf\+
Subscribe
X9drd-7jln4f
Subscribe
X9drd-7ln4f
Subscribe
X9drd-7ln4f-jbod
Subscribe
X9drd-ef
Subscribe
X9drd-if
Subscribe
X9dre-ln4f
Subscribe
X9dre-tf\+
Subscribe
X9drff
Subscribe
X9drff-7
Subscribe
X9drff-7\+
Subscribe
X9drff-7g\+
Subscribe
X9drff-7t\+
Subscribe
X9drff-7tg\+
Subscribe
X9drff-i\+
Subscribe
X9drff-ig\+
Subscribe
X9drff-it\+
Subscribe
X9drff-itg\+
Subscribe
X9drfr
Subscribe
X9drg-hf
Subscribe
X9drg-hf\+
Subscribe
X9drg-htf
Subscribe
X9drg-htf\+
Subscribe
X9drh-7f
Subscribe
X9drh-7tf
Subscribe
X9drh-if
Subscribe
X9drh-itf
Subscribe
X9dri-f
Subscribe
X9dri-ln4f\+
Subscribe
X9drl-3f
Subscribe
X9drl-ef
Subscribe
X9drl-if
Subscribe
X9drt-f
Subscribe
X9drt-h6f
Subscribe
X9drt-h6ibff
Subscribe
X9drt-h6ibqf
Subscribe
X9drt-hf\+
Subscribe
X9drt-ibff
Subscribe
X9drt-ibqf
Subscribe
X9drw-3ln4f\+
Subscribe
X9drw-3tf\+
Subscribe
X9drw-7tpf\+
Subscribe
X9drw-itpf\+
Subscribe
X9drx\+-f
Subscribe
X9qr7-tf
Subscribe
X9qr7-tf-jbod
Subscribe
X9qr7-tf\+
Subscribe
X9qri-f
Subscribe
X9qri-f\+
Subscribe
X9sbaa-f
Subscribe
X9sca-f
Subscribe
X9scd-f
Subscribe
X9sce-f
Subscribe
X9scff-f
Subscribe
X9sci-ln4f
Subscribe
X9scl-f
Subscribe
X9scl\+-f
Subscribe
X9scm-f
Subscribe
X9scm-iif
Subscribe
X9spu-f
Subscribe
X9srd-f
Subscribe
X9sre-3f
Subscribe
X9sre-f
Subscribe
X9srg-f
Subscribe
X9sri-3f
Subscribe
X9sri-f
Subscribe
X9srl-f
Subscribe
X9srw-f
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2013-3543 | The web interface in the Intelligent Platform Management Interface (IPMI) implementation on Supermicro H8DC*, H8DG*, H8SCM-F, H8SGL-F, H8SM*, X7SP*, X8DT*, X8SI*, X9DAX-*, X9DB*, X9DR*, X9QR*, X9SBAA-F, X9SC*, X9SPU-F, and X9SR* devices relies on JavaScript code on the client for authorization checks, which allows remote authenticated users to bypass intended access restrictions via a crafted request, related to the PrivilegeCallBack function. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2024-08-06T16:14:56.568Z
Reserved: 2013-05-21T00:00:00.000Z
Link: CVE-2013-3609
No data.
Status : Deferred
Published: 2013-09-08T03:17:39.603
Modified: 2025-04-11T00:51:21.963
Link: CVE-2013-3609
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD