CVE-2019-19642

HIGH

SuperMicro X8STi-F - Command Injection

Title source: llm
STIX 2.1

Description

On SuperMicro X8STi-F motherboards with IPMI firmware 2.06 and BIOS 02.68, the Virtual Media feature allows OS Command Injection by authenticated attackers who can send HTTP requests to the IPMI IP address. This requires a POST to /rpc/setvmdrive.asp with shell metacharacters in ShareHost or ShareName. The attacker can achieve a persistent backdoor.

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://www.dark-sec.net/2019/12/supermicro-ipmi-exploitation.html

Scores

CVSS v3 8.8
EPSS 0.1904
EPSS Percentile 97.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (2)
supermicro/x8sti-f_bios 02.68
supermicro/x8sti-f_firmware 2.06
Published Dec 08, 2019
Tracked Since Feb 18, 2026