OS Command Injection Vulnerability in SuperMicro Motherboards
CVE-2019-19642
8.8HIGH
What is CVE-2019-19642?
The Virtual Media feature on SuperMicro X8STi-F motherboards can be exploited by authenticated attackers through OS Command Injection. By sending a specially crafted HTTP POST request to the IPMI IP address, attackers can utilize shell metacharacters within the ShareHost or ShareName fields, leading to potential system compromise. This vulnerability allows for the establishment of a persistent backdoor, enabling unauthorized access to the affected systems.
References
EPSS Score
23% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved