GPU VulnDB

Database/Firmware, BMC & network fabric

Supermicro BMC (IPMI web interface, XSS): Further injection point in the same BMC web stack

CVE-2023-40288Firmware, BMC & network fabriccurated

Impact

Further injection point in the same BMC web stack; the payoff is a hijacked administrative session with out-of-band control of the server.

Who can reach it

Network reach to the BMC web interface plus operator interaction.

What to do

BMC firmware flash per board, bundled with the batch.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.