Multiple security vulnerabilities have been detected in the IPMI firmware utilized by Supermicro baseboard management controllers (BMCs). These vulnerabilities, labeled CVE-2023-40284 through CVE-2023-40290, span from High to Critical severity levels, potentially granting unauthorized individuals root access to the BMC system. BMCs, which are specialized processors located on server motherboards, facilitate remote system management tasks like hardware monitoring, fan speed regulation, and update the UEFI system firmware. The brief explainer of each of the vulnerabilities is as below: CVE-2023-40284, CVE-2023-40287, and CVE-2023-40288 are the three cross-site scripting (XSS) flaws with a severity of 9.6 that allow remote, unauthenticated attackers to execute arbitrary JavaScript code within the context of a logged-in BMC user. CVE-2023-40285 and CVE-2023-40286 have a severity of 8.6 and both are cross-site scripting (XSS) flaws that allow remote, unauthenticated attackers to execute arbitrary JavaScript code within the context of a logged-in BMC user by altering the browser cookies or local storage. CVE-2023-40289 has a severity of 9.1 is An operating system command injection vulnerability that permits the execution of malicious code with administrative privileges. CVE-2023-40290 has a severity of 8.3 is a cross-site scripting (XSS) flaw that empowers remote, unauthenticated attackers to execute arbitrary JavaScript code within the context of a logged-in BMC user, when using Internet Explorer 11 on Windows. Currently, there is no evidence of malicious exploitation of these vulnerabilities in the wild. Nonetheless, it's noteworthy that more than 70,000 Supermicro IPMI web interfaces were publicly accessible on the internet as of October 2023. These vulnerabilities pose a potential risk, as they could be leveraged to compromise BMC systems, granting attackers access to the server's operating system, the ability to flash malicious firmware, and the potential to move laterally within the internal network, thereby compromising other hosts.
A growing security concern is emerging within enterprise environments through the widespread use of browser extensions, particularly AI-powered extensions. While organizations incr...
Microsoft has released its June 2026 Patch Tuesday security updates, addressing 66 vulnerabilities, including one actively exploited zero-day and one publicly disclosed flaw. Among...
France's digital affairs directorate, DINUM, has confirmed a security incident involving Tchap, the encrypted messaging platform used by public-sector employees. The breach was...