Database/Firmware, BMC & network fabric
Supermicro BMC (IPMI web interface, XSS): Another injection point in the BMC web interface, lower-impact than
CVE-2023-40285Firmware, BMC & network fabriccurated
Impact
Another injection point in the BMC web interface, lower-impact than its siblings but usable for the same session-hijack chain toward virtual media and firmware flash.
Who can reach it
Network reach to the BMC web UI plus an operator loading the affected page.
What to do
BMC firmware flash per board; same batch as the rest of the 2023 Supermicro BMC advisories, so fix them together rather than one at a time.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.