Database/Firmware, BMC & network fabric
Supermicro BMC (IPMI web interface, XSS): Script injection in the BMC management UI, scope-changing because
CVSS 8.3CVE-2023-40287Firmware, BMC & network fabriccurated
Impact
Script injection in the BMC management UI, scope-changing because the compromised session controls power, console and firmware on the physical node.
Who can reach it
Network reach to the BMC web interface plus operator interaction.
What to do
BMC firmware flash per board. Same rollout as the rest of the batch; the interim control is network isolation of the BMC plane, not browser hygiene alone.
References
Related entries
- Supermicro BMC (IPMI web interface, XSS): Further injection point in the same BMC web stackCVE-2023-40288 · Supermicro BMC (IPMI web interface, XSS)High
- Supermicro BMC (IPMI web interface, XSS): Another injection point in the BMC web interface, lower-impact thanCVE-2023-40285 · Supermicro BMC (IPMI web interface, XSS)Medium
- Supermicro BMC (IPMI web interface, XSS): Stored/reflected script injection in the BMC web UICVE-2023-40284 · Supermicro BMC (IPMI web interface, XSS)High
- Supermicro BMC (IPMI web interface, XSS via IE11): Injection that fires specifically through Internet Explorer 11CVE-2023-40290 · Supermicro BMC (IPMI web interface, XSS via IE11)High
- shim (HTTP boot): Out-of-bounds write from a crafted HTTP response during network bootCVE-2023-40547 · shim (HTTP boot)High
- AMI AptioV UEFI BIOS (EDK II network stack, DHCPv6 client): Buffer overflow in the firmware's DHCPv6 client, triggeredCVE-2023-45230 · AMI AptioV UEFI BIOS (EDK II network stack, DHCPv6 client)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.