CVE-2023-33413

high-risk
Published 2023-12-07

The configuration functionality in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions through 3.17.02, allows remote authenticated users to execute arbitrary commands.

Do I need to act?

~
2.5% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
8
CVSS 8.8/10 High
NETWORK / LOW complexity

Affected Products (20)

M11Sdv-4C-Ln4F Firmware
M11Sdv-4Ct-Ln4F Firmware
M11Sdv-8C-Ln4F Firmware
M11Sdv-8Ct-Ln4F Firmware
M11Sdv-8C\+-Ln4F Firmware
C9X299-Pg Firmware
C9X299-Pg300 Firmware
C9X299-Pg300F Firmware
C9X299-Pgf Firmware
C9X299-Pgf-L Firmware
C9X299-Rpgf Firmware
C9X299-Rpgf-L Firmware
B13Dee Firmware
B13Det Firmware
B13See-Cpu-25G Firmware
B13Seg Firmware
H13Dsg-O-Cpu Firmware
H13Dsg-O-Cpu-D Firmware
H13Dsg-Om Firmware
H13Dsh Firmware

Affected Vendors

69
/ 100
high-risk
Severity 30/34 · Critical
Exploitability 6/34 · Minimal
Exposure 33/34 · Critical