Directory Traversal Vulnerability in Supermicro IPMI
CVE-2013-6785

4.3MEDIUM

Key Information:

Vendor

Supermicro

Vendor
CVE Published:
23 January 2020

What is CVE-2013-6785?

A directory traversal vulnerability exists in the url_redirect.cgi script of Supermicro's IPMI firmware prior to version SMT_X9_315. This flaw allows authenticated attackers to exploit the url_name parameter to gain unauthorized access and read sensitive files from the underlying file system. Proper security practices should be implemented to mitigate the risks posed by this vulnerability.

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2013-6785 : Directory Traversal Vulnerability in Supermicro IPMI