Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-40289


A command injection issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker can exploit this to elevate privileges from a user with BMC administrative privileges.


Published

2024-03-27T04:15:10.220

Last Modified

2025-06-18T18:49:56.143

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 7.2 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-269

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System supermicro x11ssm-f_firmware 1.66 Yes
Hardware supermicro x11ssm-f - No
Operating System supermicro x11sae-f_firmware 1.66 Yes
Hardware supermicro x11sae-f - No
Operating System supermicro x11sse-f_firmware 1.66 Yes
Hardware supermicro x11sse-f - No

References