Hardcoded WSMan credentials in Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before 3.15 (SMT_X9_315) and firmware for Supermicro X8 generation motherboards before SMT X8 312.
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Link | Tags |
---|---|
https://support.citrix.com/article/CTX216642 | third party advisory |
http://support.citrix.com/article/CTX216642 | third party advisory |
https://community.rapid7.com/community/metasploit/blog/2013/11/05/supermicro-ipmi-firmware-vulnerabilities | third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/89045 | vdb entry third party advisory |
https://www.supermicro.com/products/nfo/files/IPMI/CVE_Update.pdf | vendor advisory |