Supermicro Intelligent Platform Management Interface(IPMI)是美国超微(Supermicro)公司的一个IPMI卡(智能平台管理接口),它可对系统进行远程控制,如远程开机、进入BIOS等。 Supermicro X9代主板中使用3.15(SMT_X9_315)之前版本固件的IPMI板卡中的Web接口中的cgi/close_window.cgiCGI应用程序中存在基于栈的缓冲区溢出漏洞。远程攻击者可借助sess_sid或ACT参数利用该漏洞执行任意代码
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2013-4408 | Samba 缓冲区错误漏洞 | |
| CVE-2013-5447 | IBM Forms Viewer 基于栈的缓冲区溢出漏洞 | |
| CVE-2013-6708 | Cisco Cloud Portal 安全漏洞 | |
| CVE-2013-3710 | Novell SUSE Lifecycle Management Server 安全漏洞 | |
| CVE-2013-6237 | ISL Online ISL Light Desktop插件远程信息泄露漏洞 | |
| CVE-2013-6840 | Siemens COMOS 本地提权漏洞 | |
| CVE-2013-7042 | Novell SUSE Lifecycle Management Server 安全漏洞 | |
| CVE-2013-3622 | Supermicro Intelligent Platform Management Interface 缓冲区溢出漏洞 | |
| CVE-2013-6224 | Livezilla 跨站脚本漏洞 | |
| CVE-2012-3047 | Cisco Scientific Atlanta D20/D30 Cable Modem 跨站脚本漏洞 | |
| CVE-2013-5404 | IBM Rational Quality Manager 跨站脚本漏洞 | |
| CVE-2013-7043 | Cisco Scientific Atlanta DPR2320R2 跨站请求伪造漏洞 |
No comments yet