Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vjvg-9vgw-x699

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

On Supermicro X10 and X11 products, a client's access privileges may be transferred to a different client that later has the same socket file descriptor number. In opportunistic circumstances, an attacker can simply connect to the virtual media service, and then connect virtual USB devices to the server managed by the BMC.

On Supermicro X10 and X11 products, a client's access privileges may be transferred to a different client that later has the same socket file descriptor number. In opportunistic circumstances, an attacker can simply connect to the virtual media service, and then connect virtual USB devices to the server managed by the BMC.

EPSS

Процентиль: 70%
0.00654
Низкий

Связанные уязвимости

CVSS3: 10
nvd
больше 6 лет назад

On Supermicro X10 and X11 products, a client's access privileges may be transferred to a different client that later has the same socket file descriptor number. In opportunistic circumstances, an attacker can simply connect to the virtual media service, and then connect virtual USB devices to the server managed by the BMC.

EPSS

Процентиль: 70%
0.00654
Низкий