Arbitrary Memory Write Vulnerability Affects Supermicro Motherboards Running Pre-4.4 BIOS Firmware
CVE-2024-36432

7.5HIGH

Key Information:

Vendor

Supermicro

Vendor
CVE Published:
15 July 2024

What is CVE-2024-36432?

An arbitrary memory write vulnerability was identified in several Supermicro motherboards, specifically the X11DPG-HGX2, X11PDG-QT, X11PDG-OT, and X11PDG-SN models. This issue arises from flaws in the BIOS firmware versions prior to 4.4, which could potentially allow attackers to manipulate memory contents, leading to unauthorized access and execution of arbitrary code. The vulnerability poses serious threats to the integrity of systems utilizing these motherboards, necessitating prompt updates and security measures to safeguard against exploitation. For more information, refer to Supermicro's security advisories.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

.
CVE-2024-36432 : Arbitrary Memory Write Vulnerability Affects Supermicro Motherboards Running Pre-4.4 BIOS Firmware