RCE inside BMC OS using SNMP service configuration in Supermicro BMC IPMI firmware
BINARLY team has discovered a remote code execution vulnerability in the web server component of Supermicro BMC IPMI firmware, allowing a potential attacker to execute arbitrary code inside the BMC operating system as the root user.
Image preview
Get started today, Ship and Buy Software You Can Prove Is Safe
Book a live tour to watch Binarly validate SBOM/CBOM, surface exploitable risks, and chart a path to post-quantum readiness.
Potential Impact
A potential attacker can exploit this vulnerability to elevate privileges from a user with administrative privileges of IPMI web application to BMC system root. Running arbitrary code on the BMC operating system allows to make the attack persistent during a BMC component reboot and to perform lateral movement within compromised infrastructure, infecting other endpoints.
Image preview
Vulnerability Information
- BINARLY internal vulnerability identifier: BRLY-2023-030
- Supermicro PSIRT assigned CVE identifier: CVE-2023-33413
- BINARLY calculated CVSS v3.1: 9.1 Critical AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- Supermicro PSIRT calculated CVSS v3.1: 8.3 High AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Image preview
Get started today, Ship and Buy Software You Can Prove Is Safe
Book a live tour to watch Binarly validate SBOM/CBOM, surface exploitable risks with reachability and exploitation maturity scoring, and chart a measurable path to post-quantum readiness.