CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

supermicro

x11sae-f_firmware

10 known vulnerabilities · sorted by CVSS score

CVE-2023-33413
HIGH8.8

The configuration functionality in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions through 3.17.02, allows remote authenticated users to execute arbitrary commands.

supermicro / m11sdv-4c-ln4f_firmware+361
Network
Published Dec 7, 2023
CVE-2023-33412
HIGH8.8

The web interface in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions before 3.17.02, allows remote authenticated users to execute arbitrary commands via a crafted request targeting vulnerable cgi endpoints.

supermicro / m11sdv-4c-ln4f_firmware+361
Network
Published Dec 7, 2023
CVE-2023-40287
HIGH8.3

An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue.

supermicro / x11ssm-f_firmware+2
Network
Published Mar 27, 2024
CVE-2023-40290
HIGH8.3

An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue that affects Internet Explorer 11 on Windows.

supermicro / x11ssm-f_firmware+2
Network
Published Mar 27, 2024
CVE-2023-40288
HIGH8.3

An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue.

supermicro / x11ssm-f_firmware+2
Network
Published Mar 27, 2024
CVE-2023-40284
HIGH8.3

An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue.

supermicro / x11ssm-f_firmware+2
Network
Published Mar 27, 2024
CVE-2023-40286
HIGH8.3

An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue.

supermicro / x11ssm-f_firmware+2
Network
Published Mar 27, 2024
CVE-2023-33411
HIGH7.5

A web server in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions up to 3.17.02, allows remote unauthenticated users to perform directory traversal, potentially disclosing sensitive information.

supermicro / m11sdv-4c-ln4f_firmware+361
Network
Published Dec 7, 2023
CVE-2023-40289
HIGH7.2

A command injection issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker can exploit this to elevate privileges from a user with BMC administrative privileges.

supermicro / x11ssm-f_firmware+2
Network
Published Mar 27, 2024
CVE-2023-40285
MEDIUM6.5

An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue.

supermicro / x11ssm-f_firmware+2
Network
Published Mar 27, 2024