vendor:
SuperMicro IPMI
by:
Metin Yunus Kandemir
8.8
CVSS
HIGH
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: SuperMicro IPMI
Affected Version From: X10DRH-iT motherboards with BIOS 2.0a and IPMI firmware 03.40
Affected Version To: BIOS 3.2 and firmware 03.88
Patch Exists: YES
Related CWE: CVE-2020-15046
CPE: h:supermicro:x10drh-it
Platforms Tested:
2020
SuperMicro IPMI 03.40 – Cross-Site Request Forgery (Add Admin)
The web interface on Supermicro X10DRH-iT motherboards with BIOS 2.0a and IPMI firmware 03.40 allows remote attackers to exploit a cgi/config_user.cgi CSRF issue to add new admin users.
Mitigation:
Upgrade to BIOS 3.2 and firmware 03.88.