PT-2023-2915 · Supermicro · Supermicro X11Sse-F

CVE-2022-43309

·

Publicado

2023-01-15

·

Atualizado

2023-05-16

CVSS v2.0

6.2

Média

VetorAV:L/AC:L/Au:S/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions Supermicro X11SSL-CF HW Rev 1.01, BMC firmware version 1.63
Description The issue is related to the PMBus interface of the VRM module in Supermicro BMC controllers, where there is an incorrect assignment of permissions for a critical resource. Exploitation of this issue can allow an attacker to physically disable the CPU without the possibility of subsequent recovery. Researchers from the University of Birmingham discovered this vulnerability, which has been named PMFault, and it can be used to damage servers without physical access but with privileged access to the operating system.
Recommendations For Supermicro X11SSL-CF HW Rev 1.01, BMC firmware version 1.63, update the firmware to a version that contains the fix for this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Permission

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-02883
CVE-2022-43309

Produtos afetados

Supermicro X11Sse-F