Supermicro X11 Devices Vulnerable to XSS Attack
CVE-2023-40285

Currently unrated

Key Information:

Vendor

Supermicro

Vendor
CVE Published:
27 March 2024

What is CVE-2023-40285?

A cross-site scripting (XSS) vulnerability has been identified in Supermicro X11 series devices, including the X11SSM-F, X11SAE-F, and X11SSE-F models running firmware version 1.66. This flaw enables attackers to execute arbitrary scripts in the context of users viewing affected web pages, potentially leading to unauthorized access and manipulation of sensitive information. Organizations utilizing these devices should implement immediate mitigation measures as detailed in the security advisories provided by Supermicro.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-40285 : Supermicro X11 Devices Vulnerable to XSS Attack