Database/Firmware, BMC & network fabric
Supermicro BMC (IPMI web interface): Part of the same 2023 Supermicro BMC web-interface batch
CVE-2023-40286Firmware, BMC & network fabriccurated
Impact
Part of the same 2023 Supermicro BMC web-interface batch - an injection flaw in the management UI that feeds the session-hijack-to-firmware-flash chain.
Who can reach it
Network reach to the BMC web interface; operator interaction for the injection to land.
What to do
BMC firmware flash per board, bundled with the rest of the batch. Score not independently confirmed - treat it as equivalent to its siblings for prioritisation.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.