A command injection issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker can exploit this to elevate privileges from a user with BMC administrative privileges.
2024-03-27T04:15:10.220
2025-06-18T18:49:56.143
Analyzed
CVSSv3.1: 7.2 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | supermicro | x11ssm-f_firmware | 1.66 | Yes |
Hardware | supermicro | x11ssm-f | - | No |
Operating System | supermicro | x11sae-f_firmware | 1.66 | Yes |
Hardware | supermicro | x11sae-f | - | No |
Operating System | supermicro | x11sse-f_firmware | 1.66 | Yes |
Hardware | supermicro | x11sse-f | - | No |