9.8

CVE-2023-35861

Exploit

A shell-injection vulnerability in email notifications on Supermicro motherboards (such as H12DST-B before 03.10.35) allows remote attackers to inject execute arbitrary commands as root on the BMC.

Data is provided by the National Vulnerability Database (NVD)
SupermicroH12dst-b Firmware Version < 03.10.35
   SupermicroH12dst-b Version-
SupermicroX13dai-t Firmware Version-
   SupermicroX13dai-t Version-
SupermicroX13ddw-a Firmware Version-
   SupermicroX13ddw-a Version-
SupermicroX13deg-oa Firmware Version-
   SupermicroX13deg-oa Version-
SupermicroX13deg-oad Firmware Version-
   SupermicroX13deg-oad Version-
SupermicroX13deg-pvc Firmware Version-
   SupermicroX13deg-pvc Version-
SupermicroX13deg-qt Firmware Version-
   SupermicroX13deg-qt Version-
SupermicroX13dei Firmware Version-
   SupermicroX13dei Version-
SupermicroX13dei-t Firmware Version-
   SupermicroX13dei-t Version-
SupermicroX13dem Firmware Version-
   SupermicroX13dem Version-
SupermicroX13det-b Firmware Version-
   SupermicroX13det-b Version-
SupermicroX13dgu Firmware Version-
   SupermicroX13dgu Version-
SupermicroX13dsf-a Firmware Version-
   SupermicroX13dsf-a Version-
SupermicroX13qeh+ Firmware Version-
   SupermicroX13qeh+ Version-
SupermicroX13sae Firmware Version-
   SupermicroX13sae Version-
SupermicroX13sae-f Firmware Version-
   SupermicroX13sae-f Version-
SupermicroX13san-c Firmware Version-
   SupermicroX13san-c Version-
SupermicroX13san-c-wohs Firmware Version-
   SupermicroX13san-c-wohs Version-
SupermicroX13san-e Firmware Version-
   SupermicroX13san-e Version-
SupermicroX13san-e-wohs Firmware Version-
   SupermicroX13san-e-wohs Version-
SupermicroX13san-h Firmware Version-
   SupermicroX13san-h Version-
SupermicroX13san-h-wohs Firmware Version-
   SupermicroX13san-h-wohs Version-
SupermicroX13san-l Firmware Version-
   SupermicroX13san-l Version-
SupermicroX13san-l-wohs Firmware Version-
   SupermicroX13san-l-wohs Version-
SupermicroX13saq Firmware Version-
   SupermicroX13saq Version-
SupermicroX13sav-lvds Firmware Version-
   SupermicroX13sav-lvds Version-
SupermicroX13sav-ps Firmware Version-
   SupermicroX13sav-ps Version-
SupermicroX13saz-f Firmware Version-
   SupermicroX13saz-f Version-
SupermicroX13saz-q Firmware Version-
   SupermicroX13saz-q Version-
SupermicroX13sedw-f Firmware Version-
   SupermicroX13sedw-f Version-
SupermicroX13seed-f Firmware Version-
   SupermicroX13seed-f Version-
SupermicroX13seed-sf Firmware Version-
   SupermicroX13seed-sf Version-
SupermicroX13sefr-a Firmware Version-
   SupermicroX13sefr-a Version-
SupermicroX13sei-f Firmware Version-
   SupermicroX13sei-f Version-
SupermicroX13sei-tf Firmware Version-
   SupermicroX13sei-tf Version-
SupermicroX13sem-f Firmware Version-
   SupermicroX13sem-f Version-
SupermicroX13sem-tf Firmware Version-
   SupermicroX13sem-tf Version-
SupermicroX13set-g Firmware Version-
   SupermicroX13set-g Version-
SupermicroX13set-gc Firmware Version-
   SupermicroX13set-gc Version-
SupermicroX13sew-f Firmware Version-
   SupermicroX13sew-f Version-
SupermicroX13sew-tf Firmware Version-
   SupermicroX13sew-tf Version-
SupermicroX13sra-tf Firmware Version-
   SupermicroX13sra-tf Version-
SupermicroX13srn-e Firmware Version-
   SupermicroX13srn-e Version-
SupermicroX13srn-e-wohs Firmware Version-
   SupermicroX13srn-e-wohs Version-
SupermicroX13srn-h Firmware Version-
   SupermicroX13srn-h Version-
SupermicroX13srn-h-wohs Firmware Version-
   SupermicroX13srn-h-wohs Version-
SupermicroX13swa-tf Firmware Version-
   SupermicroX13swa-tf Version-
SupermicroH13dsg-o-cpu Firmware Version-
   SupermicroH13dsg-o-cpu Version-
SupermicroH13dsh Firmware Version-
   SupermicroH13dsh Version-
SupermicroH13sae-mf Firmware Version-
   SupermicroH13sae-mf Version-
SupermicroH13srd-f Firmware Version-
   SupermicroH13srd-f Version-
SupermicroH13ssf Firmware Version-
   SupermicroH13ssf Version-
SupermicroH13ssh Firmware Version-
   SupermicroH13ssh Version-
SupermicroH13ssl-n Firmware Version-
   SupermicroH13ssl-n Version-
SupermicroH13ssl-nt Firmware Version-
   SupermicroH13ssl-nt Version-
SupermicroH13sst-g Firmware Version-
   SupermicroH13sst-g Version-
SupermicroH13sst-gc Firmware Version-
   SupermicroH13sst-gc Version-
SupermicroH13ssw Firmware Version-
   SupermicroH13ssw Version-
SupermicroX12dai-n6 Firmware Version-
   SupermicroX12dai-n6 Version-
SupermicroX12ddw-a6 Firmware Version-
   SupermicroX12ddw-a6 Version-
SupermicroX12dgo-6 Firmware Version-
   SupermicroX12dgo-6 Version-
SupermicroX12dgq-r Firmware Version-
   SupermicroX12dgq-r Version-
SupermicroX12dgu Firmware Version-
   SupermicroX12dgu Version-
SupermicroX12dhm-6 Firmware Version-
   SupermicroX12dhm-6 Version-
SupermicroX12dpd-a6m25 Firmware Version-
   SupermicroX12dpd-a6m25 Version-
SupermicroX12dpfr-an6 Firmware Version-
   SupermicroX12dpfr-an6 Version-
SupermicroX12dpg-ar Firmware Version-
   SupermicroX12dpg-ar Version-
SupermicroX12dpg-oa6 Firmware Version-
   SupermicroX12dpg-oa6 Version-
SupermicroX12dpg-qbt6 Firmware Version-
   SupermicroX12dpg-qbt6 Version-
SupermicroX12dpg-qr Firmware Version-
   SupermicroX12dpg-qr Version-
SupermicroX12dpg-qt6 Firmware Version-
   SupermicroX12dpg-qt6 Version-
SupermicroX12dpg-u6 Firmware Version-
   SupermicroX12dpg-u6 Version-
SupermicroX12dpi-n6 Firmware Version-
   SupermicroX12dpi-n6 Version-
SupermicroX12dpi-nt6 Firmware Version-
   SupermicroX12dpi-nt6 Version-
SupermicroX12dpl-i6 Firmware Version-
   SupermicroX12dpl-i6 Version-
SupermicroX12dpl-nt6 Firmware Version-
   SupermicroX12dpl-nt6 Version-
SupermicroX12dpt-b6 Firmware Version-
   SupermicroX12dpt-b6 Version-
SupermicroX12dpt-pt46 Firmware Version-
   SupermicroX12dpt-pt46 Version-
SupermicroX12dpt-pt6 Firmware Version-
   SupermicroX12dpt-pt6 Version-
SupermicroX12dpu-6 Firmware Version-
   SupermicroX12dpu-6 Version-
SupermicroX12dsc-6 Firmware Version-
   SupermicroX12dsc-6 Version-
SupermicroX12qch+ Firmware Version-
   SupermicroX12qch+ Version-
SupermicroX12sae Firmware Version-
   SupermicroX12sae Version-
SupermicroX12sae-5 Firmware Version-
   SupermicroX12sae-5 Version-
SupermicroX12sca-5f Firmware Version-
   SupermicroX12sca-5f Version-
SupermicroX12sca-f Firmware Version-
   SupermicroX12sca-f Version-
SupermicroX12scq Firmware Version-
   SupermicroX12scq Version-
SupermicroX12scv-lvds Firmware Version-
   SupermicroX12scv-lvds Version-
SupermicroX12scv-w Firmware Version-
   SupermicroX12scv-w Version-
SupermicroX12scz-f Firmware Version-
   SupermicroX12scz-f Version-
SupermicroX12scz-qf Firmware Version-
   SupermicroX12scz-qf Version-
SupermicroX12scz-tln4f Firmware Version-
   SupermicroX12scz-tln4f Version-
SupermicroX12spa-tf Firmware Version-
   SupermicroX12spa-tf Version-
SupermicroX12sped-f Firmware Version-
   SupermicroX12sped-f Version-
SupermicroX12spg-nf Firmware Version-
   SupermicroX12spg-nf Version-
SupermicroX12spi-tf Firmware Version-
   SupermicroX12spi-tf Version-
SupermicroX12spl-f Firmware Version-
   SupermicroX12spl-f Version-
SupermicroX12spl-ln4f Firmware Version-
   SupermicroX12spl-ln4f Version-
SupermicroX12spm-ln4f Firmware Version-
   SupermicroX12spm-ln4f Version-
SupermicroX12spm-ln6tf Firmware Version-
   SupermicroX12spm-ln6tf Version-
SupermicroX12spm-tf Firmware Version-
   SupermicroX12spm-tf Version-
SupermicroX12spo-f Firmware Version-
   SupermicroX12spo-f Version-
SupermicroX12spo-ntf Firmware Version-
   SupermicroX12spo-ntf Version-
SupermicroX12spt-g Firmware Version-
   SupermicroX12spt-g Version-
SupermicroX12spt-gc Firmware Version-
   SupermicroX12spt-gc Version-
SupermicroX12spt-pt Firmware Version-
   SupermicroX12spt-pt Version-
SupermicroX12spw-f Firmware Version-
   SupermicroX12spw-f Version-
SupermicroX12spw-tf Firmware Version-
   SupermicroX12spw-tf Version-
SupermicroX12spz-ln4f Firmware Version-
   SupermicroX12spz-ln4f Version-
SupermicroX12spz-spln6f Firmware Version-
   SupermicroX12spz-spln6f Version-
SupermicroX12std-f Firmware Version-
   SupermicroX12std-f Version-
SupermicroX12ste-f Firmware Version-
   SupermicroX12ste-f Version-
SupermicroX12sth-f Firmware Version-
   SupermicroX12sth-f Version-
SupermicroX12sth-ln4f Firmware Version-
   SupermicroX12sth-ln4f Version-
SupermicroX12sth-sys Firmware Version-
   SupermicroX12sth-sys Version-
SupermicroX12stl-f Firmware Version-
   SupermicroX12stl-f Version-
SupermicroX12stl-if Firmware Version-
   SupermicroX12stl-if Version-
SupermicroX12stn-c Firmware Version-
   SupermicroX12stn-c Version-
SupermicroX12stn-c-wohs Firmware Version-
   SupermicroX12stn-c-wohs Version-
SupermicroX12stn-e Firmware Version-
   SupermicroX12stn-e Version-
SupermicroX12stn-e-wohs Firmware Version-
   SupermicroX12stn-e-wohs Version-
SupermicroX12stn-h Firmware Version-
   SupermicroX12stn-h Version-
SupermicroX12stn-h-wohs Firmware Version-
   SupermicroX12stn-h-wohs Version-
SupermicroX12stn-l Firmware Version-
   SupermicroX12stn-l Version-
SupermicroX12stn-l-wohs Firmware Version-
   SupermicroX12stn-l-wohs Version-
SupermicroX12stw-f Firmware Version-
   SupermicroX12stw-f Version-
SupermicroX12stw-tf Firmware Version-
   SupermicroX12stw-tf Version-
SupermicroH12ssw-ntr Firmware Version-
   SupermicroH12ssw-ntr Version-
SupermicroH12ssw-ntl Firmware Version-
   SupermicroH12ssw-ntl Version-
SupermicroH12ssw-nt Firmware Version-
   SupermicroH12ssw-nt Version-
SupermicroH12ssw-inr Firmware Version-
   SupermicroH12ssw-inr Version-
SupermicroH12ssw-inl Firmware Version-
   SupermicroH12ssw-inl Version-
SupermicroH12ssw-in Firmware Version-
   SupermicroH12ssw-in Version-
SupermicroH12ssw-an6 Firmware Version-
   SupermicroH12ssw-an6 Version-
SupermicroH12sst-ps Firmware Version-
   SupermicroH12sst-ps Version-
SupermicroH12ssl-nt Firmware Version-
   SupermicroH12ssl-nt Version-
SupermicroH12ssl-i Firmware Version-
   SupermicroH12ssl-i Version-
SupermicroH12ssl-ct Firmware Version-
   SupermicroH12ssl-ct Version-
SupermicroH12ssl-c Firmware Version-
   SupermicroH12ssl-c Version-
SupermicroH12ssg-anp6 Firmware Version-
   SupermicroH12ssg-anp6 Version-
SupermicroH12ssg-an6 Firmware Version-
   SupermicroH12ssg-an6 Version-
SupermicroH12ssfr-an6 Firmware Version-
   SupermicroH12ssfr-an6 Version-
SupermicroH12ssff-an6 Firmware Version-
   SupermicroH12ssff-an6 Version-
SupermicroH12dsu-inr Firmware Version-
   SupermicroH12dsu-inr Version-
SupermicroH12dsu-in Firmware Version-
   SupermicroH12dsu-in Version-
SupermicroH12dst-b Firmware Version-
   SupermicroH12dst-b Version-
SupermicroH12dsi-nt6 Firmware Version-
   SupermicroH12dsi-nt6 Version-
SupermicroH12dsi-n6 Firmware Version-
   SupermicroH12dsi-n6 Version-
SupermicroH12dsg-q-cpu6 Firmware Version-
   SupermicroH12dsg-q-cpu6 Version-
SupermicroH12dsg-o-cpu Firmware Version-
   SupermicroH12dsg-o-cpu Version-
SupermicroH12dgq-nt6 Firmware Version-
   SupermicroH12dgq-nt6 Version-
SupermicroH12dgo-6 Firmware Version-
   SupermicroH12dgo-6 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.97% 0.753
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.