CVE-2020-15046
HIGHSupermicro X10DRH-iT BIOS 2.0a and IPMI Firmware 03.40 - Cross-Site Request Forgery via cgi/config_user.cgi
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2020-15046. PoCs published by Metin Yunus Kandemir.
AI-analyzed exploit summary This is a CSRF PoC that exploits a vulnerability in SuperMicro IPMI WebInterface to add a new admin user. The exploit uses a crafted HTML form to submit a POST request to the vulnerable endpoint without requiring authentication.
Description
The web interface on Supermicro X10DRH-iT motherboards with BIOS 2.0a and IPMI firmware 03.40 allows remote attackers to exploit a cgi/config_user.cgi CSRF issue to add new admin users. The fixed versions are BIOS 3.2 and firmware 03.88.
Exploits (2)
This is a CSRF PoC that exploits a vulnerability in SuperMicro IPMI WebInterface to add a new admin user. The exploit uses a crafted HTML form to submit a POST request to the vulnerable endpoint without requiring authentication.
This is a CSRF exploit that adds a new admin user to SuperMicro IPMI by submitting a crafted POST request to the vulnerable endpoint. The PoC is a simple HTML form that automates the attack.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H