Divulgación de vulnerabilidades:
This disclosure communicates that an external group contacted Supermicro about the potential vulnerability of Supermicro products.
Agradecimientos:
Supermicro would like to acknowledge the work done by the researchers from the University of Birmingham in the UK for discovering a potential vulnerability in the X11SSL-CF motherboard.
Hallazgos:
El controlador de gestión de la placa (BMC) tiene un bus de circuito interintegrado (I²C), que puede permitir que los cambios de tensión se salgan del rango de funcionamiento especificado para la CPU y, por tanto, afectar a los cálculos normales.
CVE:
- CVE: CVE-2022-43309
- Gravedad: Alta
- Encontrado: Externamente
Productos afectados:
Products affected are the Supermicro X11, X12, H11, and H12 product lines that have the Intelligent Platform Management Interface (IPMI).
Solución:
All affected Supermicro motherboard SKUs will require a BMC update to mitigate this potential vulnerability.
Supermicro will release the following firmware updates to mitigate this potential vulnerability:
- New signed BMC firmware for all affected Supermicro motherboard SKUs
Tenga en cuenta:
- Si dispone de firmware BMC OEM, póngase en contacto con su representante técnico.
- If you have unsigned BMC firmware and prefer to keep it, please contact technical support team at Supermicro.
- Los productos X11 y H11 requieren firmware BMC firmado. Es importante tener en cuenta que, una vez actualizado, el firmware BMC firmado no puede revertirse a un firmware BMC sin firmar.
An updated BMC firmware had been created. Supermicro is currently testing and validating affected products. Please check Release Notes for the resolution.