OS Command Injection Vulnerability in SuperMicro Motherboards
CVE-2019-19642

8.8HIGH

Key Information:

Vendor

Supermicro

Vendor
CVE Published:
8 December 2019

What is CVE-2019-19642?

The Virtual Media feature on SuperMicro X8STi-F motherboards can be exploited by authenticated attackers through OS Command Injection. By sending a specially crafted HTTP POST request to the IPMI IP address, attackers can utilize shell metacharacters within the ShareHost or ShareName fields, leading to potential system compromise. This vulnerability allows for the establishment of a persistent backdoor, enabling unauthorized access to the affected systems.

References

EPSS Score

23% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.