CVE-2023-40289: Supermicro x11sae-F Firmware

High severity, CVSS 7.2. EPSS: 18.3% chance of exploitation in the next 30 days.

A command injection issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker can exploit this to elevate privileges from a user with BMC administrative privileges.

Affected products

Published 2024-03-27. Last modified 2026-06-17.