ID

VAR-E-201308-0403


CVE

cve_id:CVE-2013-3607

Trust: 0.3

sources: BID: 62094

TITLE

Supermicro IPMI Web Interface Multiple Stack-Based Buffer Overflow Vulnerabilities

Trust: 0.3

sources: BID: 62094

DESCRIPTION

Supermicro IPMI is prone to multiple stack-based buffer-overflow vulnerabilities because it fails to perform adequate boundary checks on user-supplied data.
An attacker can exploit these issues to execute arbitrary code in the context of the device that uses the affected interface. Failed exploit attempts will likely crash the device.

Trust: 0.3

sources: BID: 62094

AFFECTED PRODUCTS

vendor:supermodel:micro computer supermicro x9srl-fscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9sri-fscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9sri-3fscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9srg-fscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9sre-fscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9sre-3fscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9srd-fscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9spu-fscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9scm-iifscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9scm-fscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9scl-fscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9scl+-fscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9sci-ln4fscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9scff-fscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9sce-fscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9scd-fscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9sca-fscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9sbaa-fscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9qri-f+scope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9qri-fscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9qr7-tf-jbodscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9qr7-tf+scope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9qr7-tfscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9drx+-fscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9drw-itpfscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9drw-7tpf+scope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9drw-3tf+scope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9drw-3ln4f+scope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9drt-ibqfscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9drt-ibffscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9drt-hf+scope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9drt-h6ibqfscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9drt-h6ibffscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9drt-h6fscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9drt-fscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9drl-ifscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9drl-efscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9drl-3fscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9dri-ln4f+scope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9dri-fscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9drh-itfscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9drh-ifscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9drh-7tfscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9drh-7fscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9drg-htf+scope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9drg-htfscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9drg-hf+scope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9drg-hfscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9drfrscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9drff-itg+scope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9drff-it+scope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9drff-ig+scope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9drff-i+scope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9drff-7tg+scope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9drff-7t+scope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9drff-7g+scope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9drff-7+scope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9drff-7scope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9drffscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9dre-tf+scope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9dre-ln4fscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9drd-ifscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9drd-efscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9drd-7ln4f-jbodscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9drd-7ln4fscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9drd-7jln4fscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9dr7-tf+scope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9dr7-ln4f-jbodscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9dr7-ln4fscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9dr3-ln4f+scope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9dr3-fscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9dbu-ifscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9dbu-3fscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9dbl-ifscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9dbl-3fscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9dbi-tpfscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9dbi-fscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9db3-tpfscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9db3-fscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9dax-itfscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9dax-if-hftscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9dax-ifscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9dax-7tfscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9dax-7f-hftscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x9dax-7fscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x8siu-fscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x8sit-hfscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x8sit-fscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x8sil-fscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x8sie-ln4fscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x8sie-fscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x8sia-fscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x8si6-fscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x8dtu-ln4f+-lrscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x8dtu-ln4f+scope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x8dtu-6tf+-lrscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x8dtu-6tf+scope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x8dtu-6f+-lrscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x8dtu-6f+scope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x8dtn+-f-lrscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x8dtn+-fscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x8dtl-ifscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x8dtl-6fscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x8dtl-3fscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x7spt-df-d525+scope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x7spt-df-d525scope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x7spe-hf-d525scope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x7spe-hfscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x7spe-h-d525scope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x7spa-hf-d525scope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro x7spa-hfscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro h8sml-ifscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro h8sml-iscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro h8sml-7fscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro h8sml-7scope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro h8sme-fscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro h8sgl-fscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro h8scm-fscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro h8dgu-ln4f+scope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro h8dgu-fscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro h8dgt-hlibqfscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro h8dgt-hlfscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro h8dgt-hibqfscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro h8dgt-hfscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro h8dgi-fscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro h8dgg-qfscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro h8dg6-fscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro h8dct-ibqfscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro h8dct-hln4fscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro h8dct-hibqfscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro h8dct-fscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro h8dcl-ifscope: - version: -

Trust: 0.3

vendor:supermodel:micro computer supermicro h8dcl-6fscope: - version: -

Trust: 0.3

vendor:citrixmodel:netscaler t1scope:eqversion:0

Trust: 0.3

vendor:citrixmodel:netscaler service delivery appliancescope:eqversion:0

Trust: 0.3

vendor:citrixmodel:netscaler gatewayscope:eqversion:0

Trust: 0.3

vendor:citrixmodel:netscaler application delivery controllerscope:eqversion:0

Trust: 0.3

vendor:citrixmodel:command center appliancescope:eqversion:0

Trust: 0.3

vendor:citrixmodel:cloudbridgescope:eqversion:0

Trust: 0.3

sources: BID: 62094

EXPLOIT

The researcher has created a proof-of-concept to demonstrate these issues. Please see the references for more information.

Trust: 0.3

sources: BID: 62094

PRICE

Free

Trust: 0.3

sources: BID: 62094

TYPE

Boundary Condition Error

Trust: 0.3

sources: BID: 62094

CREDITS

J. Alex Halderman

Trust: 0.3

sources: BID: 62094

EXTERNAL IDS

db:CERT/CCid:VU#648646

Trust: 0.3

db:NVDid:CVE-2013-3607

Trust: 0.3

db:BIDid:62094

Trust: 0.3

sources: BID: 62094

REFERENCES

url:http://www.supermicro.com/about/

Trust: 0.3

url:http://www.kb.cert.org/vuls/id/648646

Trust: 0.3

url:http://support.citrix.com/article/ctx216642

Trust: 0.3

sources: BID: 62094

SOURCES

db:BIDid:62094

LAST UPDATE DATE

2022-07-27T09:18:54.090000+00:00


SOURCES UPDATE DATE

db:BIDid:62094date:2016-09-09T15:00:00

SOURCES RELEASE DATE

db:BIDid:62094date:2013-08-30T00:00:00