CVE-2024-36435

An issue was discovered on Supermicro BMC firmware in select X11, X12, H12, B12, X13, H13, and B13 motherboards (and CMM6 modules). An unauthenticated user can post crafted data to the interface that triggers a stack buffer overflow, and may lead to arbitrary remote code execution on a BMC.
Configurations

No configuration.

History

01 Aug 2024, 13:52

Type Values Removed Values Added
CWE CWE-121

12 Jul 2024, 12:49

Type Values Removed Values Added
Summary
  • (es) Se descubrió un problema en el firmware Supermicro BMC en placas base seleccionadas X11, X12, H12, B12, X13, H13 y B13 (y módulos CMM6). Un usuario no autenticado puede publicar datos manipulados en la interfaz, lo que desencadena un desbordamiento de búfer en la región stack de la memoria y puede provocar la ejecución remota arbitraria de código en un BMC.

11 Jul 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-11 21:15

Updated : 2024-08-01 13:52


NVD link : CVE-2024-36435

Mitre link : CVE-2024-36435

CVE.ORG link : CVE-2024-36435


JSON object : View

Products Affected

No product.

CWE
CWE-121

Stack-based Buffer Overflow