Back to Database
Status published
Medium
CVE-2018-13787
Certain Supermicro X11S, X10, X9, X8SI, K1SP, C9X299, C7, B1,...
Vulnerability Description
Certain Supermicro X11S, X10, X9, X8SI, K1SP, C9X299, C7, B1, A2, and A1 products have a misconfigured Descriptor Region, allowing OS programs to modify firmware.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-13787
Credits & Attribution
No credits recorded in the NVD database.
References
More from supermicro
View All →CVE-2022-43309
Supermicro X11SSL-CF HW Rev 1.01, BMC firmware v1.63 was discovered...
Unknown
0
CVE-2020-15046
The web interface on Supermicro X10DRH-iT motherboards with BIOS 2.0a...
High
8.8
CVE-2019-19642
On SuperMicro X8STi-F motherboards with IPMI firmware 2.06 and BIOS...
High
8.8
CVE-2019-16650
On Supermicro X10 and X11 products, a client's access privileges...
Critical
10
CVE-2019-16649
On Supermicro H11, H12, M11, X9, X10, and X11 products,...
Critical
10
Affected Vendor
supermicro
View all reports →Affected Software
x11ssz firmware, x11ssv firmware, x11ssql firmware, x11ssq firmware, x11ssn firmware, x11srm firmware, x11sra firmware, x11sba firmware, x11sat firmware, x11sae m firmware, x11sae firmware, x10srw firmware, x10srm firmware, x10srl firmware, x10sri firmware, x10srh firmware, x10srg firmware, x10srd firmware, x10sra firmware, x10sdvt firmware, x10sdvf firmware, x10sde firmware, x10sddf firmware, x10sba firmware, x10qrh firmware, x10dsn firmware, x10dscp firmware, x10dsc firmware, x10drx firmware, x10drwn firmware, x10drw firmware, x10drux firmware, x10drul firmware, x10dru firmware, x10drts firmware, x10drtps firmware, x10drtl firmware, x10drth firmware, x10drtb firmware, x10drt firmware, x10drs firmware, x10drln firmware, x10drlc firmware, x10drl firmware, x10dri1 firmware, x10drh4 firmware, x10drh firmware, x10drgo firmware, x10drgh firmware, x10drg firmware, x10drfr firmware, x10drfg firmware, x10drff firmware, x10drdl firmware, x10drd firmware, x10drc firmware, x10dgo firmware, x10ddwn firmware, x10ddwi firmware, x10ddw4 firmware, x10ddw3 firmware, x10dax firmware, x10dali firmware, x10dal firmware, x10dai firmware, b10drt firmware, b10dri firmware, b10drg firmware, x9sae firmware, x9drth firmware, x9drgqf firmware, x9drffp firmware, x9drf firmware, x9dbl firmware, x8siu firmware, x8sit firmware, x8sil firmware, x8sie firmware, x8sia firmware, k1spi firmware, k1spes firmware, c9x299 firmware, c7z97oc firmware, c7z97mf firmware, c7z87oc firmware, c7z370l firmware, c7z370i firmware, c7z270p firmware, c7z270m firmware, c7z270l firmware, c7z270cg firmware, c7z270c firmware, c7z170oce firmware, c7z170o firmware, c7z170 firmware, c7x99oc firmware, c7q270 firmware, c7h270 firmware, c7b250 firmware, b1sd2tf firmware, b1sa4 firmware, b1dri firmware, a2sav firmware, a2sap firmware, a2san firmware, a1srm firmware, a1sam firmware, a1sai1 firmware, a1sai firmware, a1sa firmware
Vulnerable Versions:
Unknown
Timeline
Official Publish:
July 9th, 2018
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.