GPU VulnDB

Database/Firmware, BMC & network fabric

Supermicro BMC (IPMI web interface, XSS): Script injection in the BMC management UI, scope-changing because

CVE-2023-40287Firmware, BMC & network fabriccurated

Impact

Script injection in the BMC management UI, scope-changing because the compromised session controls power, console and firmware on the physical node.

Who can reach it

Network reach to the BMC web interface plus operator interaction.

What to do

BMC firmware flash per board. Same rollout as the rest of the batch; the interim control is network isolation of the BMC plane, not browser hygiene alone.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.