CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

Search Vulnerabilities

 Software

Searching vulnerabilities affecting “supermicro”

12 vulnerabilities found for “supermicro”

CVE-2023-33412
HIGH8.8

The web interface in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions before 3.17.02, allows remote authenticated users to execute arbitrary commands via a crafted request targeting vulnerable cgi endpoints.

supermicro / m11sdv-4c-ln4f_firmware+361
Network
Published Dec 7, 2023
CVE-2023-33411
HIGH7.5

A web server in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions up to 3.17.02, allows remote unauthenticated users to perform directory traversal, potentially disclosing sensitive information.

supermicro / m11sdv-4c-ln4f_firmware+361
Network
Published Dec 7, 2023
CVE-2023-33413
HIGH8.8

The configuration functionality in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions through 3.17.02, allows remote authenticated users to execute arbitrary commands.

supermicro / m11sdv-4c-ln4f_firmware+361
Network
Published Dec 7, 2023
CVE-2023-34853
HIGH7.8

Buffer Overflow vulnerability in Supermicro motherboard X12DPG-QR 1.4b allows local attackers to hijack control flow via manipulation of SmcSecurityEraseSetupVar variable.

supermicro / x12dai-n6_firmware+270
Local
Published Aug 22, 2023
CVE-2022-43309
MEDIUM5.5

Supermicro X11SSL-CF HW Rev 1.01, BMC firmware v1.63 was discovered to contain insecure permissions.

supermicro / x11ssl-cf_firmware+146
Local
Published Apr 7, 2023
CVE-2013-3620
HIGH7.5

Hardcoded WSMan credentials in Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before 3.15 (SMT_X9_315) and firmware for Supermicro X8 generation motherboards before SMT X8 312.

supermicro / smt_x9_firmware+4
Network
Published Jan 2, 2020
CVE-2013-3619
HIGH8.1

Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before SMT_X9_317 and firmware for Supermicro X8 generation motherboards before SMT X8 312 contain harcoded private encryption keys for the (1) Lighttpd web server SSL interface and the (2) Dropbear SSH daemon.

supermicro / smt_x9_firmware+4
Network
Published Jan 2, 2020
CVE-2019-19642
HIGH8.8

On SuperMicro X8STi-F motherboards with IPMI firmware 2.06 and BIOS 02.68, the Virtual Media feature allows OS Command Injection by authenticated attackers who can send HTTP requests to the IPMI IP address. This requires a POST to /rpc/setvmdrive.asp with shell metacharacters in ShareHost or ShareName. The attacker can achieve a persistent backdoor.

supermicro / x8sti-f_bios+1
Network
Published Dec 8, 2019
CVE-2019-16650
CRITICAL10.0

On Supermicro X10 and X11 products, a client's access privileges may be transferred to a different client that later has the same socket file descriptor number. In opportunistic circumstances, an attacker can simply connect to the virtual media service, and then connect virtual USB devices to the server managed by the BMC.

supermicro / x11dai-n_firmware+264
Network
Published Sep 21, 2019
CVE-2019-16649
CRITICAL10.0

On Supermicro H11, H12, M11, X9, X10, and X11 products, a combination of encryption and authentication problems in the virtual media service allows capture of BMC credentials and data transferred over virtual media devices. Attackers can use captured credentials to connect virtual USB devices to the server managed by the BMC.

supermicro / x10drt-libq_firmware+337
Network
Published Sep 21, 2019
CVE-2019-13131
CRITICAL9.8

Super Micro SuperDoctor 5, when restrictions are not implemented in agent.cfg, allows remote attackers to execute arbitrary commands via NRPE.

supermicro / superdoctor_5
Network
Published Jul 1, 2019
CVE-2018-13787
MEDIUM6.7

Certain Supermicro X11S, X10, X9, X8SI, K1SP, C9X299, C7, B1, A2, and A1 products have a misconfigured Descriptor Region, allowing OS programs to modify firmware.

supermicro / x11ssz_firmware+109
Local
Published Jul 9, 2018