Database/Firmware, BMC & network fabric
Supermicro BIOS (arbitrary memory write, X11DPH series): Arbitrary memory write from firmware context on X11DPH boards
CVSS 7.5CVE-2024-36433Firmware, BMC & network fabriccurated
Impact
Arbitrary memory write from firmware context on X11DPH boards, giving a high-privileged local attacker control below the operating system.
Who can reach it
Local high-privilege access.
What to do
Flash Supermicro BIOS 4.4 or later. Cold reboot required.
References
Related entries
- Supermicro BIOS SMM callout (X11DPH-T / X11DPH-Tq): Execution in System Management Mode, the most privileged executionCVE-2024-36434 · Supermicro BIOS SMM callout (X11DPH-T / X11DPH-Tq)High
- Dell SmartFabric OS10 (uncontrolled resource consumption): A remote unauthenticated host can exhaust resources on anCVE-2024-37125 · Dell SmartFabric OS10 (uncontrolled resource consumption)High
- Sunbird DCIM dcTrack v9.1.2 - ticket location RBAC: Incorrect access control lets an attacker create or update ticketsCVE-2024-37775 · Sunbird DCIM dcTrack v9.1.2 - ticket location RBACHigh
- Dell SmartFabric OS10 (command injection): Command injection in SmartFabric OS10 10.5.5.4-10.5.5.10 and 10.5.6.xCVE-2024-38486 · Dell SmartFabric OS10 (command injection)High
- Linux kernel - RDMA/rxe unreliable datagram responder, drivers/infiniband/sw/rxe/rxe_resp.c: The IB architecture says aCVE-2024-40992 · Linux kernel - RDMA/rxe unreliable datagram responder, drivers/infiniband/sw/rxe/rxe_resp.cHigh
- Linux kernel NVMe-oF RDMA target (nvmet, uninitialised completion-entry result field): This is a straight kernel-stackCVE-2024-41079 · Linux kernel NVMe-oF RDMA target (nvmet, uninitialised completion-entry result field)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.