vendor:
Onboard IPMI
by:
hdm, juan vazquez
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Onboard IPMI
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: CVE-2013-3623
CPE: a:supermicro:ipmi_controller_firmware
Platforms Tested: Unix
2013
Supermicro Onboard IPMI close_window.cgi Buffer Overflow
This module exploits a buffer overflow on the Supermicro Onboard IPMI controller web interface. The vulnerability exists on the close_window.cgi CGI application, and is due to the insecure usage of strcpy. In order to get a session, the module will execute system() from libc with an arbitrary CMD payload sent on the User-Agent header. This module has been tested successfully on Supermicro Onboard IPMI (X9SCL/X9SCM) with firmware SMT_X9_214.
Mitigation:
Unknown