Directory Traversal Vulnerability in Supermicro IPMI
CVE-2013-6785
4.3MEDIUM
What is CVE-2013-6785?
A directory traversal vulnerability exists in the url_redirect.cgi script of Supermicro's IPMI firmware prior to version SMT_X9_315. This flaw allows authenticated attackers to exploit the url_name parameter to gain unauthorized access and read sensitive files from the underlying file system. Proper security practices should be implemented to mitigate the risks posed by this vulnerability.
References
EPSS Score
31% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
