Database/Firmware, BMC & network fabric
Supermicro BMC (IPMI web interface, XSS): Another injection point in the BMC web interface, lower-impact than
CVSS 6.5CVE-2023-40285Firmware, BMC & network fabriccurated
Impact
Another injection point in the BMC web interface, lower-impact than its siblings but usable for the same session-hijack chain toward virtual media and firmware flash.
Who can reach it
Network reach to the BMC web UI plus an operator loading the affected page.
What to do
BMC firmware flash per board; same batch as the rest of the 2023 Supermicro BMC advisories, so fix them together rather than one at a time.
References
Related entries
- Supermicro BMC (IPMI web interface, XSS): Stored/reflected script injection in the BMC web UICVE-2023-40284 · Supermicro BMC (IPMI web interface, XSS)High
- Supermicro BMC (IPMI web interface, XSS): Script injection in the BMC management UI, scope-changing becauseCVE-2023-40287 · Supermicro BMC (IPMI web interface, XSS)High
- Supermicro BMC (IPMI web interface, XSS): Further injection point in the same BMC web stackCVE-2023-40288 · Supermicro BMC (IPMI web interface, XSS)High
- EDK II NetworkPkg (DHCPv6 Advertise, IA_NA/IA_TA option parsing): An integer underflow when parsingCVE-2023-45229 · EDK II NetworkPkg (DHCPv6 Advertise, IA_NA/IA_TA option parsing)Medium
- EDK II NetworkPkg (IPv6 Neighbor Discovery Redirect handling): A truncated ND Redirect message drives an out-of-boundsCVE-2023-45231 · EDK II NetworkPkg (IPv6 Neighbor Discovery Redirect handling)Medium
- Linux kernel (drivers/infiniband/ulp/ipoib): The IPoIB multicast join task drops its lock mid-iteration, letting aCVE-2023-52587 · Linux kernel (drivers/infiniband/ulp/ipoib)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.