CVE-2023-35861

Exp

A shell-injection vulnerability in email notifications on Supermicro motherboards (such as H12DST-B before 03.10.35) allows remote attackers to inject execute arbitrary commands as root on the BMC.

Published: 2023-07-31 Last update: 2024-11-21 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2023-35861 is rated High Exploit Risk (82.1/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 1.21%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Public exploit references (Exploit-DB) for CVE-2023-35861

EDB-ID Source Kind Published Link
nvd_ref exploit_tag Exploit-DB ↗

Exploit prediction scoring system (EPSS) score for CVE-2023-35861

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-04-25 0.97% 1.21% +0.24%
2 2025-11-21 2.14% 0.97% -1.17%
3 2025-11-18 2.14%

Full EPSS history (12 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2023-35861

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
9.8 3.1 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:H)
They could widely tamper with or forge data—trust in the data is badly hurt.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
3.9 5.9 [email protected]

Weakness enumeration for CVE-2023-35861

Affected software / configurations for CVE-2023-35861

Vendor Product Version Raw CPE
supermicro h12dst-b_firmware < 03.10.35 cpe:2.3:o:supermicro:h12dst-b_firmware:*:*:*:*:*:*:*:*
supermicro x13dai-t_firmware cpe:2.3:o:supermicro:x13dai-t_firmware:-:*:*:*:*:*:*:*
supermicro x13ddw-a_firmware cpe:2.3:o:supermicro:x13ddw-a_firmware:-:*:*:*:*:*:*:*
supermicro x13deg-oa_firmware cpe:2.3:o:supermicro:x13deg-oa_firmware:-:*:*:*:*:*:*:*
supermicro x13deg-oad_firmware cpe:2.3:o:supermicro:x13deg-oad_firmware:-:*:*:*:*:*:*:*
supermicro x13deg-pvc_firmware cpe:2.3:o:supermicro:x13deg-pvc_firmware:-:*:*:*:*:*:*:*
supermicro x13deg-qt_firmware cpe:2.3:o:supermicro:x13deg-qt_firmware:-:*:*:*:*:*:*:*
supermicro x13dei_firmware cpe:2.3:o:supermicro:x13dei_firmware:-:*:*:*:*:*:*:*
supermicro x13dei-t_firmware cpe:2.3:o:supermicro:x13dei-t_firmware:-:*:*:*:*:*:*:*
supermicro x13dem_firmware cpe:2.3:o:supermicro:x13dem_firmware:-:*:*:*:*:*:*:*
supermicro x13det-b_firmware cpe:2.3:o:supermicro:x13det-b_firmware:-:*:*:*:*:*:*:*
supermicro x13dgu_firmware cpe:2.3:o:supermicro:x13dgu_firmware:-:*:*:*:*:*:*:*
supermicro x13dsf-a_firmware cpe:2.3:o:supermicro:x13dsf-a_firmware:-:*:*:*:*:*:*:*
supermicro x13qeh\+_firmware cpe:2.3:o:supermicro:x13qeh\+_firmware:-:*:*:*:*:*:*:*
supermicro x13sae_firmware cpe:2.3:o:supermicro:x13sae_firmware:-:*:*:*:*:*:*:*
supermicro x13sae-f_firmware cpe:2.3:o:supermicro:x13sae-f_firmware:-:*:*:*:*:*:*:*
supermicro x13san-c_firmware cpe:2.3:o:supermicro:x13san-c_firmware:-:*:*:*:*:*:*:*
supermicro x13san-c-wohs_firmware cpe:2.3:o:supermicro:x13san-c-wohs_firmware:-:*:*:*:*:*:*:*
supermicro x13san-e_firmware cpe:2.3:o:supermicro:x13san-e_firmware:-:*:*:*:*:*:*:*
supermicro x13san-e-wohs_firmware cpe:2.3:o:supermicro:x13san-e-wohs_firmware:-:*:*:*:*:*:*:*
supermicro x13san-h_firmware cpe:2.3:o:supermicro:x13san-h_firmware:-:*:*:*:*:*:*:*
supermicro x13san-h-wohs_firmware cpe:2.3:o:supermicro:x13san-h-wohs_firmware:-:*:*:*:*:*:*:*
supermicro x13san-l_firmware cpe:2.3:o:supermicro:x13san-l_firmware:-:*:*:*:*:*:*:*
supermicro x13san-l-wohs_firmware cpe:2.3:o:supermicro:x13san-l-wohs_firmware:-:*:*:*:*:*:*:*
supermicro x13saq_firmware cpe:2.3:o:supermicro:x13saq_firmware:-:*:*:*:*:*:*:*
supermicro x13sav-lvds_firmware cpe:2.3:o:supermicro:x13sav-lvds_firmware:-:*:*:*:*:*:*:*
supermicro x13sav-ps_firmware cpe:2.3:o:supermicro:x13sav-ps_firmware:-:*:*:*:*:*:*:*
supermicro x13saz-f_firmware cpe:2.3:o:supermicro:x13saz-f_firmware:-:*:*:*:*:*:*:*
supermicro x13saz-q_firmware cpe:2.3:o:supermicro:x13saz-q_firmware:-:*:*:*:*:*:*:*
supermicro x13sedw-f_firmware cpe:2.3:o:supermicro:x13sedw-f_firmware:-:*:*:*:*:*:*:*
supermicro x13seed-f_firmware cpe:2.3:o:supermicro:x13seed-f_firmware:-:*:*:*:*:*:*:*
supermicro x13seed-sf_firmware cpe:2.3:o:supermicro:x13seed-sf_firmware:-:*:*:*:*:*:*:*
supermicro x13sefr-a_firmware cpe:2.3:o:supermicro:x13sefr-a_firmware:-:*:*:*:*:*:*:*
supermicro x13sei-f_firmware cpe:2.3:o:supermicro:x13sei-f_firmware:-:*:*:*:*:*:*:*
supermicro x13sei-tf_firmware cpe:2.3:o:supermicro:x13sei-tf_firmware:-:*:*:*:*:*:*:*
supermicro x13sem-f_firmware cpe:2.3:o:supermicro:x13sem-f_firmware:-:*:*:*:*:*:*:*
supermicro x13sem-tf_firmware cpe:2.3:o:supermicro:x13sem-tf_firmware:-:*:*:*:*:*:*:*
supermicro x13set-g_firmware cpe:2.3:o:supermicro:x13set-g_firmware:-:*:*:*:*:*:*:*
supermicro x13set-gc_firmware cpe:2.3:o:supermicro:x13set-gc_firmware:-:*:*:*:*:*:*:*
supermicro x13sew-f_firmware cpe:2.3:o:supermicro:x13sew-f_firmware:-:*:*:*:*:*:*:*
supermicro x13sew-tf_firmware cpe:2.3:o:supermicro:x13sew-tf_firmware:-:*:*:*:*:*:*:*
supermicro x13sra-tf_firmware cpe:2.3:o:supermicro:x13sra-tf_firmware:-:*:*:*:*:*:*:*
supermicro x13srn-e_firmware cpe:2.3:o:supermicro:x13srn-e_firmware:-:*:*:*:*:*:*:*
supermicro x13srn-e-wohs_firmware cpe:2.3:o:supermicro:x13srn-e-wohs_firmware:-:*:*:*:*:*:*:*
supermicro x13srn-h_firmware cpe:2.3:o:supermicro:x13srn-h_firmware:-:*:*:*:*:*:*:*
supermicro x13srn-h-wohs_firmware cpe:2.3:o:supermicro:x13srn-h-wohs_firmware:-:*:*:*:*:*:*:*
supermicro x13swa-tf_firmware cpe:2.3:o:supermicro:x13swa-tf_firmware:-:*:*:*:*:*:*:*
supermicro h13dsg-o-cpu_firmware cpe:2.3:o:supermicro:h13dsg-o-cpu_firmware:-:*:*:*:*:*:*:*
supermicro h13dsg-o-cpu-d_firmware cpe:2.3:o:supermicro:h13dsg-o-cpu-d_firmware:-:*:*:*:*:*:*:*
supermicro h13dsh_firmware cpe:2.3:o:supermicro:h13dsh_firmware:-:*:*:*:*:*:*:*
supermicro h13sae-mf_firmware cpe:2.3:o:supermicro:h13sae-mf_firmware:-:*:*:*:*:*:*:*
supermicro h13srd-f_firmware cpe:2.3:o:supermicro:h13srd-f_firmware:-:*:*:*:*:*:*:*
supermicro h13ssf_firmware cpe:2.3:o:supermicro:h13ssf_firmware:-:*:*:*:*:*:*:*
supermicro h13ssh_firmware cpe:2.3:o:supermicro:h13ssh_firmware:-:*:*:*:*:*:*:*
supermicro h13ssl-n_firmware cpe:2.3:o:supermicro:h13ssl-n_firmware:-:*:*:*:*:*:*:*
supermicro h13ssl-nt_firmware cpe:2.3:o:supermicro:h13ssl-nt_firmware:-:*:*:*:*:*:*:*
supermicro h13sst-g_firmware cpe:2.3:o:supermicro:h13sst-g_firmware:-:*:*:*:*:*:*:*
supermicro h13sst-gc_firmware cpe:2.3:o:supermicro:h13sst-gc_firmware:-:*:*:*:*:*:*:*
supermicro h13ssw_firmware cpe:2.3:o:supermicro:h13ssw_firmware:-:*:*:*:*:*:*:*
supermicro x12dai-n6_firmware cpe:2.3:o:supermicro:x12dai-n6_firmware:-:*:*:*:*:*:*:*
supermicro x12ddw-a6_firmware cpe:2.3:o:supermicro:x12ddw-a6_firmware:-:*:*:*:*:*:*:*
supermicro x12dgo-6_firmware cpe:2.3:o:supermicro:x12dgo-6_firmware:-:*:*:*:*:*:*:*
supermicro x12dgq-r_firmware cpe:2.3:o:supermicro:x12dgq-r_firmware:-:*:*:*:*:*:*:*
supermicro x12dgu_firmware cpe:2.3:o:supermicro:x12dgu_firmware:-:*:*:*:*:*:*:*
supermicro x12dhm-6_firmware cpe:2.3:o:supermicro:x12dhm-6_firmware:-:*:*:*:*:*:*:*
supermicro x12dpd-a6m25_firmware cpe:2.3:o:supermicro:x12dpd-a6m25_firmware:-:*:*:*:*:*:*:*
supermicro x12dpfr-an6_firmware cpe:2.3:o:supermicro:x12dpfr-an6_firmware:-:*:*:*:*:*:*:*
supermicro x12dpg-ar_firmware cpe:2.3:o:supermicro:x12dpg-ar_firmware:-:*:*:*:*:*:*:*
supermicro x12dpg-oa6_firmware cpe:2.3:o:supermicro:x12dpg-oa6_firmware:-:*:*:*:*:*:*:*
supermicro x12dpg-oa6-gd2_firmware cpe:2.3:o:supermicro:x12dpg-oa6-gd2_firmware:-:*:*:*:*:*:*:*
supermicro x12dpg-qbt6_firmware cpe:2.3:o:supermicro:x12dpg-qbt6_firmware:-:*:*:*:*:*:*:*
supermicro x12dpg-qr_firmware cpe:2.3:o:supermicro:x12dpg-qr_firmware:-:*:*:*:*:*:*:*
supermicro x12dpg-qt6_firmware cpe:2.3:o:supermicro:x12dpg-qt6_firmware:-:*:*:*:*:*:*:*
supermicro x12dpg-u6_firmware cpe:2.3:o:supermicro:x12dpg-u6_firmware:-:*:*:*:*:*:*:*
supermicro x12dpi-n6_firmware cpe:2.3:o:supermicro:x12dpi-n6_firmware:-:*:*:*:*:*:*:*
supermicro x12dpi-nt6_firmware cpe:2.3:o:supermicro:x12dpi-nt6_firmware:-:*:*:*:*:*:*:*
supermicro x12dpl-i6_firmware cpe:2.3:o:supermicro:x12dpl-i6_firmware:-:*:*:*:*:*:*:*
supermicro x12dpl-nt6_firmware cpe:2.3:o:supermicro:x12dpl-nt6_firmware:-:*:*:*:*:*:*:*
supermicro x12dpt-b6_firmware cpe:2.3:o:supermicro:x12dpt-b6_firmware:-:*:*:*:*:*:*:*
supermicro x12dpt-pt46_firmware cpe:2.3:o:supermicro:x12dpt-pt46_firmware:-:*:*:*:*:*:*:*

References for CVE-2023-35861

cvelogic Threat Intelligence