CVE-2023-40289: Supermicro x11sae-F Firmware
High severity, CVSS 7.2. EPSS: 18.3% chance of exploitation in the next 30 days.
A command injection issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker can exploit this to elevate privileges from a user with BMC administrative privileges.
Affected products
- Supermicro x11sae-F Firmware: version 1.66 only
- Supermicro x11sse-F Firmware: version 1.66 only
- Supermicro x11ssm-F Firmware: version 1.66 only
Published 2024-03-27. Last modified 2026-06-17.