ID

VAR-201909-0757


CVE

CVE-2019-16649


TITLE

plural Supermicro Vulnerabilities related to the use of hard-coded credentials in products

Trust: 0.8

sources: JVNDB: JVNDB-2019-009650

DESCRIPTION

On Supermicro H11, H12, M11, X9, X10, and X11 products, a combination of encryption and authentication problems in the virtual media service allows capture of BMC credentials and data transferred over virtual media devices. Attackers can use captured credentials to connect virtual USB devices to the server managed by the BMC. plural Supermicro The product contains a vulnerability related to the use of hard-coded credentials.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. SuperMicro Supermicro X10 and so on are all server motherboards of American SuperMicro company. A security vulnerability exists in the virtual media service in several Supermicro products. The following products and versions are affected: SuperMicro Supermicro H11; Supermicro H12; Supermicro M11; Supermicro X9; Supermicro X10; Supermicro X11

Trust: 1.71

sources: NVD: CVE-2019-16649 // JVNDB: JVNDB-2019-009650 // VULHUB: VHN-148816

AFFECTED PRODUCTS

vendor:supermicromodel:x10sdv-8c-tln4fscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x11dacscope:eqversion:1.71.5

Trust: 1.0

vendor:supermicromodel:x10drt-ptscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x10driscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x11ddw-ntscope:eqversion:1.71.5

Trust: 1.0

vendor:supermicromodel:b2ss2-mtfscope:eqversion:3.68

Trust: 1.0

vendor:supermicromodel:a1srm-ln5f-2358scope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:b10drc-nscope:eqversion:3.68

Trust: 1.0

vendor:supermicromodel:x11ssh-tfscope:eqversion:1.56

Trust: 1.0

vendor:supermicromodel:x9daiscope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:x9drfrscope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:x11spm-tfscope:eqversion:1.71.6

Trust: 1.0

vendor:supermicromodel:x10drd-intscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x9drd-c\ t\+scope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:x11dph-iscope:eqversion:1.71.5

Trust: 1.0

vendor:supermicromodel:x11dpt-bscope:eqversion:1.71.5

Trust: 1.0

vendor:supermicromodel:x10slm-fscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x10drfr-ntscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x9drt-p seriesscope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:x10drw-iscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x10slm\+-ln4fscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x10drt-hscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x9drff-7\/i\ \+scope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:x10drff-itgscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:a1sai-2550fscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x11dpt-psscope:eqversion:1.71.5

Trust: 1.0

vendor:supermicromodel:x9dr7\/e-tf\+scope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:m11sdv-8c-ln4fscope:eqversion:3.15

Trust: 1.0

vendor:supermicromodel:x11ssh-ln4fscope:eqversion:1.56

Trust: 1.0

vendor:supermicromodel:x9drg-h\ fscope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:x9drg-h\ f\+iiscope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:x11ddw-lscope:eqversion:1.71.5

Trust: 1.0

vendor:supermicromodel:x9drw-c\ f31scope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:x10sdv-tp8fscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x11sds-8cscope:eqversion:3.74.2

Trust: 1.0

vendor:supermicromodel:b10drg-ibf2scope:eqversion:3.68

Trust: 1.0

vendor:supermicromodel:x11ssh-gf-1585lscope:eqversion:1.56

Trust: 1.0

vendor:supermicromodel:x11dph-tqscope:eqversion:1.71.5

Trust: 1.0

vendor:supermicromodel:x10ddw-inscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x10sla-fscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:a1sri-2558fscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x10sdv-4c-7tp4fscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x11dgo-tscope:eqversion:1.71.5

Trust: 1.0

vendor:supermicromodel:x11dpff-snscope:eqversion:1.71.5

Trust: 1.0

vendor:supermicromodel:x11srl-fscope:eqversion:3.74.2

Trust: 1.0

vendor:supermicromodel:x10drh-cln4scope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x11dpu-ze\+scope:eqversion:1.71.5

Trust: 1.0

vendor:supermicromodel:b10drtscope:eqversion:3.68

Trust: 1.0

vendor:supermicromodel:x9scm\scope:eqversion:2.3

Trust: 1.0

vendor:supermicromodel:x11dpx-tscope:eqversion:1.71.5

Trust: 1.0

vendor:supermicromodel:x10qblscope:eqversion:3.80

Trust: 1.0

vendor:supermicromodel:x11spl-fscope:eqversion:1.71.6

Trust: 1.0

vendor:supermicromodel:x10sll-sscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:b2ss1-cfscope:eqversion:3.68

Trust: 1.0

vendor:supermicromodel:x11ssi-ln4fscope:eqversion:1.71.5

Trust: 1.0

vendor:supermicromodel:x10drd-ltpscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x10qrh\+scope:eqversion:3.80

Trust: 1.0

vendor:supermicromodel:x9qr7-tf\+scope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:x10sdv-16c-tln4f\+scope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x11ssw-fscope:eqversion:1.71.5

Trust: 1.0

vendor:supermicromodel:x11spm-tpfscope:eqversion:1.71.6

Trust: 1.0

vendor:supermicromodel:x10sdv-8c-tln4f\+scope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x11sri-ifscope:eqversion:3.75.00

Trust: 1.0

vendor:supermicromodel:x10drw-itscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x10drc-t4\+scope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x11ssh-ctfscope:eqversion:1.56

Trust: 1.0

vendor:supermicromodel:x11ssd-fscope:eqversion:3.68

Trust: 1.0

vendor:supermicromodel:x11scl-ln4fscope:eqversion:1.23.2

Trust: 1.0

vendor:supermicromodel:x9drt seriesscope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:x10drd-iscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x10drh-ctscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x11dai-nscope:eqversion:1.71.5

Trust: 1.0

vendor:supermicromodel:b9drg-3mscope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:x11dgqscope:eqversion:1.71.5

Trust: 1.0

vendor:supermicromodel:x11dpl-iscope:eqversion:1.71.5

Trust: 1.0

vendor:supermicromodel:x9srascope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:x9dr3\/i-ln4f\+scope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:x10drt-hibfscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x10dru-xscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x10sdv-2c-tp4fscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x10sdv-4c\+-tln4fscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x10dsc\+scope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x9drg-qfscope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:x11scl-ifscope:eqversion:1.23.2

Trust: 1.0

vendor:supermicromodel:x9drw-3ln4f\+\/3tf\+scope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:x11spw-tfscope:eqversion:1.71.6

Trust: 1.0

vendor:supermicromodel:b2ss1-cpuscope:eqversion:3.68

Trust: 1.0

vendor:supermicromodel:x10qbl-4scope:eqversion:3.80

Trust: 1.0

vendor:supermicromodel:x11srm-fscope:eqversion:1.31.1

Trust: 1.0

vendor:supermicromodel:x10dri-ln4\+scope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x11spa-tfscope:eqversion:1.71.5

Trust: 1.0

vendor:supermicromodel:x10drh-cscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x11ssm-fscope:eqversion:1.56

Trust: 1.0

vendor:supermicromodel:x9scl\+-fscope:eqversion:2.3

Trust: 1.0

vendor:supermicromodel:b11dpescope:eqversion:3.68

Trust: 1.0

vendor:supermicromodel:x9dr7-jln4fscope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:b10drt-ibf2scope:eqversion:3.68

Trust: 1.0

vendor:supermicromodel:b9drgscope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:x10drfrscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x9dbs-f\scope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:x10satscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x11ssl-cfscope:eqversion:1.56

Trust: 1.0

vendor:supermicromodel:x9drl-3\/ifscope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:x10dsn-tsscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x10drg-ot\+-cpuscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x10sri-fscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x11spg-tfscope:eqversion:1.71.6

Trust: 1.0

vendor:supermicromodel:x11sse-fscope:eqversion:3.68

Trust: 1.0

vendor:supermicromodel:x10dbt-tscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x9srl\scope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:x9scd seriesscope:eqversion:2.3

Trust: 1.0

vendor:supermicromodel:x10dri-tscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x9drw-7\/itpfscope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:x11sch-fscope:eqversion:1.23.2

Trust: 1.0

vendor:supermicromodel:x9qri-fscope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:x9drg-o\ f-cpuscope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:x10srm-fscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x9db3\/i-\ fscope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:x10drt-pibqscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x10drff-igscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x10srascope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x11ssw-fscope:eqversion:3.85.00

Trust: 1.0

vendor:supermicromodel:x10dgqscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x9dbl-3\/i\scope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:x10sdv-2c-7tp4fscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x10sdv-6c-tln4fscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x10sll\+-fscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x9srg-fscope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:b1sd2-16c-tfscope:eqversion:3.68

Trust: 1.0

vendor:supermicromodel:x10drc-ln4\+scope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x11spi-tfscope:eqversion:1.71.6

Trust: 1.0

vendor:supermicromodel:x10sdv-2c-tln2fscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x10drsscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x10srd-fscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x10obi-cpuscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x11dpfr-snscope:eqversion:1.71.5

Trust: 1.0

vendor:supermicromodel:b11spe-cpu-25gscope:eqversion:3.68

Trust: 1.0

vendor:supermicromodel:x10sdv-fscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x11ssmscope:eqversion:1.56

Trust: 1.0

vendor:supermicromodel:x11sslscope:eqversion:1.56

Trust: 1.0

vendor:supermicromodel:b11spe-cpu-tfscope:eqversion:3.68

Trust: 1.0

vendor:supermicromodel:x9drh-if-nvscope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:a1sai-2750fscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x10dri-t4\+scope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x11ssh-gtf-1585scope:eqversion:1.56

Trust: 1.0

vendor:supermicromodel:x11dsf-escope:eqversion:1.71.5

Trust: 1.0

vendor:supermicromodel:x11dpi-ntscope:eqversion:1.71.5

Trust: 1.0

vendor:supermicromodel:x11sca-fscope:eqversion:1.71.5

Trust: 1.0

vendor:supermicromodel:x9drx\+-fscope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:x11sca-wscope:eqversion:1.71.5

Trust: 1.0

vendor:supermicromodel:x10dgo-tscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x10drd-itpscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:a1srm-2558fscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:m11sdv-8ct-ln4fscope:eqversion:3.15

Trust: 1.0

vendor:supermicromodel:x10drl-itscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x10drd-ltscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x9dax-7\/if-hftscope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:a1srm-ln7f-2358scope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x11scl-fscope:eqversion:1.23.2

Trust: 1.0

vendor:supermicromodel:x9drd-l\/ifscope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:x11dsc\+scope:eqversion:1.74

Trust: 1.0

vendor:supermicromodel:x10srg-fscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x9qr7-tfscope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:x10drd-itscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x10drg-qscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:b10driscope:eqversion:3.68

Trust: 1.0

vendor:supermicromodel:x9drw-7\/itpf\+scope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:x11dpg-snscope:eqversion:1.71.5

Trust: 1.0

vendor:supermicromodel:x9drd-efscope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:x11sph-nctfscope:eqversion:1.71.6

Trust: 1.0

vendor:supermicromodel:x10qbl-4ctscope:eqversion:3.80

Trust: 1.0

vendor:supermicromodel:x9drt-hf\+scope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:b2ss1-h-mtfscope:eqversion:3.68

Trust: 1.0

vendor:supermicromodel:x9srw-fscope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:x10drt-libqscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:b2ss2-h-mtfscope:eqversion:3.68

Trust: 1.0

vendor:supermicromodel:x9drl-7\/efscope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:x11dpt-lscope:eqversion:3.74

Trust: 1.0

vendor:supermicromodel:x9sae\scope:eqversion:2.3

Trust: 1.0

vendor:supermicromodel:x9sci-ln4\scope:eqversion:2.3

Trust: 1.0

vendor:supermicromodel:x10slx-fscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x10drw-etscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x9dax-7\/i\ fscope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:b9drtscope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:x10drt-b\+scope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x11dpfr-sscope:eqversion:1.71.5

Trust: 1.0

vendor:supermicromodel:x10sdv-7tp4fscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x10slh-fscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x11ssw-4tfscope:eqversion:1.56

Trust: 1.0

vendor:supermicromodel:x9drg-h\ f\+scope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:x11sds-12cscope:eqversion:3.74.2

Trust: 1.0

vendor:supermicromodel:x11scw-fscope:eqversion:3.75.00

Trust: 1.0

vendor:supermicromodel:x10srw-fscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x11sdd-18c-fscope:eqversion:3.68

Trust: 1.0

vendor:supermicromodel:x11ssh-fscope:eqversion:1.56

Trust: 1.0

vendor:supermicromodel:b1sd1-tfscope:eqversion:3.68

Trust: 1.0

vendor:supermicromodel:x10drd-intpscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x10srh-cln4fscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:a1srm-ln7f-2758scope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x9dr3\/i-fscope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:m11sdv-4c-ln4fscope:eqversion:3.15

Trust: 1.0

vendor:supermicromodel:b10drg-tpscope:eqversion:3.68

Trust: 1.0

vendor:supermicromodel:x10sdv-7tp8fscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x10sdv-12c-tln4fscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:b2ss2-fscope:eqversion:3.68

Trust: 1.0

vendor:supermicromodel:x10sdv-4c-tln4fscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:a1sri-2358fscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x10sdv-4c\+-tp4fscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:b10drg-ibfscope:eqversion:3.68

Trust: 1.0

vendor:supermicromodel:x10sdd-fscope:eqversion:3.68

Trust: 1.0

vendor:supermicromodel:x11sdd-8c-fscope:eqversion:3.68

Trust: 1.0

vendor:supermicromodel:a1sam-2750fscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:b1sd2-tfscope:eqversion:3.68

Trust: 1.0

vendor:supermicromodel:b10drt-tpscope:eqversion:3.68

Trust: 1.0

vendor:supermicromodel:x11dpu-z\+scope:eqversion:1.71.5

Trust: 1.0

vendor:supermicromodel:x11scm-fscope:eqversion:1.23.2

Trust: 1.0

vendor:supermicromodel:x9drff\scope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:x10drg-o\+-cpuscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x10sdv-6c\+-tln4fscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x9drh-7\/i\ fscope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:x10drg-htscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x11dpg-ot-cpuscope:eqversion:1.71.5

Trust: 1.0

vendor:supermicromodel:x11spw-ctfscope:eqversion:1.71.6

Trust: 1.0

vendor:supermicromodel:x9sre\/i seriesscope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:b9qr7\scope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:x10srh-cfscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x11qph\+scope:eqversion:1.71.5

Trust: 1.0

vendor:supermicromodel:x10sdv-4c-tln2fscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x10drfr-nscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x10sdv-16c-tln4fscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:a1sam-2550fscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x10drh-iscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x11spm-fscope:eqversion:1.71.6

Trust: 1.0

vendor:supermicromodel:x10drh-iln4scope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x11srm-vfscope:eqversion:1.31.1

Trust: 1.0

vendor:supermicromodel:x10sde-dfscope:eqversion:3.68

Trust: 1.0

vendor:supermicromodel:x11dpu-xscope:eqversion:1.71.5

Trust: 1.0

vendor:supermicromodel:x10drl-iscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x10sle-dfscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x9srh-7\ fscope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:x9drd-it\+scope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:x10dru-i\+scope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x11sds-16cscope:eqversion:3.74.2

Trust: 1.0

vendor:supermicromodel:x9qri-f\+scope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:x10sdv-2c-tp8fscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x10drw-escope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x10srm-tfscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:b9drg-escope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:x10drw-nscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:a1sri-2758fscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x10slm\+-fscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x9drw-3\/ifscope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:x9drd-7ln4f seriesscope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:x10drt-pibfscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x11dpg-qtscope:eqversion:1.71.5

Trust: 1.0

vendor:supermicromodel:x11sph-nctpfscope:eqversion:1.71.6

Trust: 1.0

vendor:supermicromodel:x9dal-3\/iscope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:b9drpscope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:x11scascope:eqversion:1.71.5

Trust: 1.0

vendor:supermicromodel:x11spa-tscope:eqversion:1.71.5

Trust: 1.0

vendor:supermicromodel:x11ssh-gtf-1585lscope:eqversion:1.56

Trust: 1.0

vendor:supermicromodel:x9srd-fscope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:x10dru-xllscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:b11qpiscope:eqversion:3.68

Trust: 1.0

vendor:supermicromodel:x11ssh-gf-1585scope:eqversion:1.56

Trust: 1.0

vendor:supermicromodel:x10sld-hfscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x11dpuscope:eqversion:1.71.5

Trust: 1.0

vendor:supermicromodel:x11scd-fscope:eqversion:3.68

Trust: 1.0

vendor:supermicromodel:x10drff-cgscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x10sll-sfscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x11opi-cpuscope:eqversion:1.71.5

Trust: 1.0

vendor:supermicromodel:x9dbu-3\/ifscope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:x10drt-lscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x9da7\/escope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:x10drw-ntscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x10qbl-ctscope:eqversion:3.80

Trust: 1.0

vendor:supermicromodel:x10sdd-16c-fscope:eqversion:3.68

Trust: 1.0

vendor:supermicromodel:x10drff-ctgscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:b10dri-nscope:eqversion:3.68

Trust: 1.0

vendor:supermicromodel:x10drt-psscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:a1sa2-2750fscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x10drfr-tscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:b10drcscope:eqversion:3.68

Trust: 1.0

vendor:supermicromodel:x10sdv-16c\+-tln4fscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x11sch-ln4fscope:eqversion:1.23.2

Trust: 1.0

vendor:supermicromodel:x10drt-pscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x9drt-h seriesscope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:x10drh-itscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x9dr7\/e-ln4fscope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:x11scm-ln8fscope:eqversion:1.23.2

Trust: 1.0

vendor:supermicromodel:x10drff-cscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x10drffscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x10sle-fscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x11dsn-tsscope:eqversion:1.71.5

Trust: 1.0

vendor:supermicromodel:x10drt-libfscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x10drl-ctscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x11dpu-vscope:eqversion:1.71.5

Trust: 1.0

vendor:supermicromodel:x11ssl-nfscope:eqversion:1.56

Trust: 1.0

vendor:supermicromodel:x10drl-cscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x9drff-7\/i\ g\+scope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:b11dptscope:eqversion:3.68

Trust: 1.0

vendor:supermicromodel:b10drt-ibfscope:eqversion:3.68

Trust: 1.0

vendor:supermicromodel:x10sdv-tln4fscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:b2ss1-fscope:eqversion:3.68

Trust: 1.0

vendor:supermicromodel:x10drl-ln4scope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x10sdv-12c\+-tln4fscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:a1srm-2758fscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x10sdv-12c-tln4f\+scope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:b9driscope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:x10sra-fscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x11ssl-fscope:eqversion:1.56

Trust: 1.0

vendor:supermicromodel:b9dr7scope:eqversion:3.3

Trust: 1.0

vendor:supermicromodel:x10qbiscope:eqversion:3.81

Trust: 1.0

vendor:supermicromodel:x11dsn-tsqscope:eqversion:1.71.5

Trust: 1.0

vendor:supermicromodel:x9sca\scope:eqversion:2.3

Trust: 1.0

vendor:supermicromodel:x11ssw-tfscope:eqversion:1.56

Trust: 1.0

vendor:supermicromodel:x10saescope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:b2ss1-mtfscope:eqversion:3.68

Trust: 1.0

vendor:supermicromodel:x10drg-hscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:m11sdv-8c\+-ln4fscope:eqversion:3.15

Trust: 1.0

vendor:supermicromodel:x11dpu-xllscope:eqversion:1.71.5

Trust: 1.0

vendor:supermicromodel:x10sld-fscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:m11sdv-4ct-ln4fscope:eqversion:3.15

Trust: 1.0

vendor:supermicromodel:x10sll-fscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x9scl\scope:eqversion:2.3

Trust: 1.0

vendor:supermicromodel:x10sle-hfscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x11dph-tscope:eqversion:1.71.5

Trust: 1.0

vendor:supermicromodel:x10ddw-iscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x11dpt-bhscope:eqversion:1.71.5

Trust: 1.0

vendor:supermicromodel:x10sdv-8c\+-ln2fscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x10drxscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x10drd-lscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x11dpi-nscope:eqversion:1.71.5

Trust: 1.0

vendor:supermicromodel:b1sd1-16c-tfscope:eqversion:3.68

Trust: 1.0

vendor:supermicromodel:x10srl-fscope:eqversion:3.83

Trust: 1.0

vendor:supermicromodel:x11dps-rescope:eqversion:1.71.5

Trust: 1.0

vendor:supermicromodel:x10sl7-fscope:eqversion:3.83

Trust: 1.0

vendor:super micro computermodel:x11dacscope: - version: -

Trust: 0.8

vendor:super micro computermodel:x11dai-nscope: - version: -

Trust: 0.8

vendor:super micro computermodel:x11dph-iscope: - version: -

Trust: 0.8

vendor:super micro computermodel:x11dph-tscope: - version: -

Trust: 0.8

vendor:super micro computermodel:x11dph-tqscope: - version: -

Trust: 0.8

vendor:super micro computermodel:x11dps-rescope: - version: -

Trust: 0.8

vendor:super micro computermodel:x11dsc+scope: - version: -

Trust: 0.8

vendor:super micro computermodel:x11dsf-escope: - version: -

Trust: 0.8

vendor:super micro computermodel:x11dsn-tsscope: - version: -

Trust: 0.8

vendor:super micro computermodel:x11dsn-tsqscope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2019-009650 // NVD: CVE-2019-16649

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2019-16649
value: CRITICAL

Trust: 1.0

NVD: CVE-2019-16649
value: CRITICAL

Trust: 0.8

CNNVD: CNNVD-201909-1012
value: MEDIUM

Trust: 0.6

VULHUB: VHN-148816
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2019-16649
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-148816
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2019-16649
baseSeverity: CRITICAL
baseScore: 10.0
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: CHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 6.0
version: 3.1

Trust: 1.0

NVD: CVE-2019-16649
baseSeverity: CRITICAL
baseScore: 10.0
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: CHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULHUB: VHN-148816 // JVNDB: JVNDB-2019-009650 // CNNVD: CNNVD-201909-1012 // NVD: CVE-2019-16649

PROBLEMTYPE DATA

problemtype:CWE-287

Trust: 1.1

problemtype:CWE-326

Trust: 1.1

problemtype:CWE-522

Trust: 1.1

problemtype:CWE-798

Trust: 0.9

sources: VULHUB: VHN-148816 // JVNDB: JVNDB-2019-009650 // NVD: CVE-2019-16649

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201909-1012

TYPE

authorization issue

Trust: 0.6

sources: CNNVD: CNNVD-201909-1012

CONFIGURATIONS

sources: JVNDB: JVNDB-2019-009650

PATCH

title:BMC/IPMI Security Vulnerabilityurl:https://www.supermicro.com/support/security_BMC_virtual_media.cfm

Trust: 0.8

title:Multiple SuperMicro Product security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=98478

Trust: 0.6

sources: JVNDB: JVNDB-2019-009650 // CNNVD: CNNVD-201909-1012

EXTERNAL IDS

db:NVDid:CVE-2019-16649

Trust: 2.5

db:JVNDBid:JVNDB-2019-009650

Trust: 0.8

db:CNNVDid:CNNVD-201909-1012

Trust: 0.7

db:VULHUBid:VHN-148816

Trust: 0.1

sources: VULHUB: VHN-148816 // JVNDB: JVNDB-2019-009650 // CNNVD: CNNVD-201909-1012 // NVD: CVE-2019-16649

REFERENCES

url:https://eclypsium.com/2019/09/03/usbanywhere-bmc-vulnerability-opens-servers-to-remote-attack/

Trust: 2.5

url:https://github.com/eclypsium/usbanywhere

Trust: 1.7

url:https://www.supermicro.com/support/security_bmc_virtual_media.cfm

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2019-16649

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-16649

Trust: 0.8

sources: VULHUB: VHN-148816 // JVNDB: JVNDB-2019-009650 // CNNVD: CNNVD-201909-1012 // NVD: CVE-2019-16649

SOURCES

db:VULHUBid:VHN-148816
db:JVNDBid:JVNDB-2019-009650
db:CNNVDid:CNNVD-201909-1012
db:NVDid:CVE-2019-16649

LAST UPDATE DATE

2024-11-23T23:08:15.698000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-148816date:2020-08-24T00:00:00
db:JVNDBid:JVNDB-2019-009650date:2019-09-26T00:00:00
db:CNNVDid:CNNVD-201909-1012date:2020-09-02T00:00:00
db:NVDid:CVE-2019-16649date:2024-11-21T04:30:52.953

SOURCES RELEASE DATE

db:VULHUBid:VHN-148816date:2019-09-21T00:00:00
db:JVNDBid:JVNDB-2019-009650date:2019-09-26T00:00:00
db:CNNVDid:CNNVD-201909-1012date:2019-09-20T00:00:00
db:NVDid:CVE-2019-16649date:2019-09-21T02:15:11.523