A shell-injection vulnerability in email notifications on Supermicro motherboards (such as H12DST-B before 03.10.35) allows remote attackers to inject execute arbitrary commands as root on the BMC.
Conclusion & alert: CVE-2023-35861 is rated High Exploit Risk (82.1/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 1.21%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-04-25 | 0.97% | 1.21% | +0.24% |
| 2 | 2025-11-21 | 2.14% | 0.97% | -1.17% |
| 3 | 2025-11-18 | — | 2.14% | — |
Full EPSS history (12 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| supermicro | h12dst-b_firmware | < 03.10.35 | cpe:2.3:o:supermicro:h12dst-b_firmware:*:*:*:*:*:*:*:* |
| supermicro | x13dai-t_firmware | — | cpe:2.3:o:supermicro:x13dai-t_firmware:-:*:*:*:*:*:*:* |
| supermicro | x13ddw-a_firmware | — | cpe:2.3:o:supermicro:x13ddw-a_firmware:-:*:*:*:*:*:*:* |
| supermicro | x13deg-oa_firmware | — | cpe:2.3:o:supermicro:x13deg-oa_firmware:-:*:*:*:*:*:*:* |
| supermicro | x13deg-oad_firmware | — | cpe:2.3:o:supermicro:x13deg-oad_firmware:-:*:*:*:*:*:*:* |
| supermicro | x13deg-pvc_firmware | — | cpe:2.3:o:supermicro:x13deg-pvc_firmware:-:*:*:*:*:*:*:* |
| supermicro | x13deg-qt_firmware | — | cpe:2.3:o:supermicro:x13deg-qt_firmware:-:*:*:*:*:*:*:* |
| supermicro | x13dei_firmware | — | cpe:2.3:o:supermicro:x13dei_firmware:-:*:*:*:*:*:*:* |
| supermicro | x13dei-t_firmware | — | cpe:2.3:o:supermicro:x13dei-t_firmware:-:*:*:*:*:*:*:* |
| supermicro | x13dem_firmware | — | cpe:2.3:o:supermicro:x13dem_firmware:-:*:*:*:*:*:*:* |
| supermicro | x13det-b_firmware | — | cpe:2.3:o:supermicro:x13det-b_firmware:-:*:*:*:*:*:*:* |
| supermicro | x13dgu_firmware | — | cpe:2.3:o:supermicro:x13dgu_firmware:-:*:*:*:*:*:*:* |
| supermicro | x13dsf-a_firmware | — | cpe:2.3:o:supermicro:x13dsf-a_firmware:-:*:*:*:*:*:*:* |
| supermicro | x13qeh\+_firmware | — | cpe:2.3:o:supermicro:x13qeh\+_firmware:-:*:*:*:*:*:*:* |
| supermicro | x13sae_firmware | — | cpe:2.3:o:supermicro:x13sae_firmware:-:*:*:*:*:*:*:* |
| supermicro | x13sae-f_firmware | — | cpe:2.3:o:supermicro:x13sae-f_firmware:-:*:*:*:*:*:*:* |
| supermicro | x13san-c_firmware | — | cpe:2.3:o:supermicro:x13san-c_firmware:-:*:*:*:*:*:*:* |
| supermicro | x13san-c-wohs_firmware | — | cpe:2.3:o:supermicro:x13san-c-wohs_firmware:-:*:*:*:*:*:*:* |
| supermicro | x13san-e_firmware | — | cpe:2.3:o:supermicro:x13san-e_firmware:-:*:*:*:*:*:*:* |
| supermicro | x13san-e-wohs_firmware | — | cpe:2.3:o:supermicro:x13san-e-wohs_firmware:-:*:*:*:*:*:*:* |
| supermicro | x13san-h_firmware | — | cpe:2.3:o:supermicro:x13san-h_firmware:-:*:*:*:*:*:*:* |
| supermicro | x13san-h-wohs_firmware | — | cpe:2.3:o:supermicro:x13san-h-wohs_firmware:-:*:*:*:*:*:*:* |
| supermicro | x13san-l_firmware | — | cpe:2.3:o:supermicro:x13san-l_firmware:-:*:*:*:*:*:*:* |
| supermicro | x13san-l-wohs_firmware | — | cpe:2.3:o:supermicro:x13san-l-wohs_firmware:-:*:*:*:*:*:*:* |
| supermicro | x13saq_firmware | — | cpe:2.3:o:supermicro:x13saq_firmware:-:*:*:*:*:*:*:* |
| supermicro | x13sav-lvds_firmware | — | cpe:2.3:o:supermicro:x13sav-lvds_firmware:-:*:*:*:*:*:*:* |
| supermicro | x13sav-ps_firmware | — | cpe:2.3:o:supermicro:x13sav-ps_firmware:-:*:*:*:*:*:*:* |
| supermicro | x13saz-f_firmware | — | cpe:2.3:o:supermicro:x13saz-f_firmware:-:*:*:*:*:*:*:* |
| supermicro | x13saz-q_firmware | — | cpe:2.3:o:supermicro:x13saz-q_firmware:-:*:*:*:*:*:*:* |
| supermicro | x13sedw-f_firmware | — | cpe:2.3:o:supermicro:x13sedw-f_firmware:-:*:*:*:*:*:*:* |
| supermicro | x13seed-f_firmware | — | cpe:2.3:o:supermicro:x13seed-f_firmware:-:*:*:*:*:*:*:* |
| supermicro | x13seed-sf_firmware | — | cpe:2.3:o:supermicro:x13seed-sf_firmware:-:*:*:*:*:*:*:* |
| supermicro | x13sefr-a_firmware | — | cpe:2.3:o:supermicro:x13sefr-a_firmware:-:*:*:*:*:*:*:* |
| supermicro | x13sei-f_firmware | — | cpe:2.3:o:supermicro:x13sei-f_firmware:-:*:*:*:*:*:*:* |
| supermicro | x13sei-tf_firmware | — | cpe:2.3:o:supermicro:x13sei-tf_firmware:-:*:*:*:*:*:*:* |
| supermicro | x13sem-f_firmware | — | cpe:2.3:o:supermicro:x13sem-f_firmware:-:*:*:*:*:*:*:* |
| supermicro | x13sem-tf_firmware | — | cpe:2.3:o:supermicro:x13sem-tf_firmware:-:*:*:*:*:*:*:* |
| supermicro | x13set-g_firmware | — | cpe:2.3:o:supermicro:x13set-g_firmware:-:*:*:*:*:*:*:* |
| supermicro | x13set-gc_firmware | — | cpe:2.3:o:supermicro:x13set-gc_firmware:-:*:*:*:*:*:*:* |
| supermicro | x13sew-f_firmware | — | cpe:2.3:o:supermicro:x13sew-f_firmware:-:*:*:*:*:*:*:* |
| supermicro | x13sew-tf_firmware | — | cpe:2.3:o:supermicro:x13sew-tf_firmware:-:*:*:*:*:*:*:* |
| supermicro | x13sra-tf_firmware | — | cpe:2.3:o:supermicro:x13sra-tf_firmware:-:*:*:*:*:*:*:* |
| supermicro | x13srn-e_firmware | — | cpe:2.3:o:supermicro:x13srn-e_firmware:-:*:*:*:*:*:*:* |
| supermicro | x13srn-e-wohs_firmware | — | cpe:2.3:o:supermicro:x13srn-e-wohs_firmware:-:*:*:*:*:*:*:* |
| supermicro | x13srn-h_firmware | — | cpe:2.3:o:supermicro:x13srn-h_firmware:-:*:*:*:*:*:*:* |
| supermicro | x13srn-h-wohs_firmware | — | cpe:2.3:o:supermicro:x13srn-h-wohs_firmware:-:*:*:*:*:*:*:* |
| supermicro | x13swa-tf_firmware | — | cpe:2.3:o:supermicro:x13swa-tf_firmware:-:*:*:*:*:*:*:* |
| supermicro | h13dsg-o-cpu_firmware | — | cpe:2.3:o:supermicro:h13dsg-o-cpu_firmware:-:*:*:*:*:*:*:* |
| supermicro | h13dsg-o-cpu-d_firmware | — | cpe:2.3:o:supermicro:h13dsg-o-cpu-d_firmware:-:*:*:*:*:*:*:* |
| supermicro | h13dsh_firmware | — | cpe:2.3:o:supermicro:h13dsh_firmware:-:*:*:*:*:*:*:* |
| supermicro | h13sae-mf_firmware | — | cpe:2.3:o:supermicro:h13sae-mf_firmware:-:*:*:*:*:*:*:* |
| supermicro | h13srd-f_firmware | — | cpe:2.3:o:supermicro:h13srd-f_firmware:-:*:*:*:*:*:*:* |
| supermicro | h13ssf_firmware | — | cpe:2.3:o:supermicro:h13ssf_firmware:-:*:*:*:*:*:*:* |
| supermicro | h13ssh_firmware | — | cpe:2.3:o:supermicro:h13ssh_firmware:-:*:*:*:*:*:*:* |
| supermicro | h13ssl-n_firmware | — | cpe:2.3:o:supermicro:h13ssl-n_firmware:-:*:*:*:*:*:*:* |
| supermicro | h13ssl-nt_firmware | — | cpe:2.3:o:supermicro:h13ssl-nt_firmware:-:*:*:*:*:*:*:* |
| supermicro | h13sst-g_firmware | — | cpe:2.3:o:supermicro:h13sst-g_firmware:-:*:*:*:*:*:*:* |
| supermicro | h13sst-gc_firmware | — | cpe:2.3:o:supermicro:h13sst-gc_firmware:-:*:*:*:*:*:*:* |
| supermicro | h13ssw_firmware | — | cpe:2.3:o:supermicro:h13ssw_firmware:-:*:*:*:*:*:*:* |
| supermicro | x12dai-n6_firmware | — | cpe:2.3:o:supermicro:x12dai-n6_firmware:-:*:*:*:*:*:*:* |
| supermicro | x12ddw-a6_firmware | — | cpe:2.3:o:supermicro:x12ddw-a6_firmware:-:*:*:*:*:*:*:* |
| supermicro | x12dgo-6_firmware | — | cpe:2.3:o:supermicro:x12dgo-6_firmware:-:*:*:*:*:*:*:* |
| supermicro | x12dgq-r_firmware | — | cpe:2.3:o:supermicro:x12dgq-r_firmware:-:*:*:*:*:*:*:* |
| supermicro | x12dgu_firmware | — | cpe:2.3:o:supermicro:x12dgu_firmware:-:*:*:*:*:*:*:* |
| supermicro | x12dhm-6_firmware | — | cpe:2.3:o:supermicro:x12dhm-6_firmware:-:*:*:*:*:*:*:* |
| supermicro | x12dpd-a6m25_firmware | — | cpe:2.3:o:supermicro:x12dpd-a6m25_firmware:-:*:*:*:*:*:*:* |
| supermicro | x12dpfr-an6_firmware | — | cpe:2.3:o:supermicro:x12dpfr-an6_firmware:-:*:*:*:*:*:*:* |
| supermicro | x12dpg-ar_firmware | — | cpe:2.3:o:supermicro:x12dpg-ar_firmware:-:*:*:*:*:*:*:* |
| supermicro | x12dpg-oa6_firmware | — | cpe:2.3:o:supermicro:x12dpg-oa6_firmware:-:*:*:*:*:*:*:* |
| supermicro | x12dpg-oa6-gd2_firmware | — | cpe:2.3:o:supermicro:x12dpg-oa6-gd2_firmware:-:*:*:*:*:*:*:* |
| supermicro | x12dpg-qbt6_firmware | — | cpe:2.3:o:supermicro:x12dpg-qbt6_firmware:-:*:*:*:*:*:*:* |
| supermicro | x12dpg-qr_firmware | — | cpe:2.3:o:supermicro:x12dpg-qr_firmware:-:*:*:*:*:*:*:* |
| supermicro | x12dpg-qt6_firmware | — | cpe:2.3:o:supermicro:x12dpg-qt6_firmware:-:*:*:*:*:*:*:* |
| supermicro | x12dpg-u6_firmware | — | cpe:2.3:o:supermicro:x12dpg-u6_firmware:-:*:*:*:*:*:*:* |
| supermicro | x12dpi-n6_firmware | — | cpe:2.3:o:supermicro:x12dpi-n6_firmware:-:*:*:*:*:*:*:* |
| supermicro | x12dpi-nt6_firmware | — | cpe:2.3:o:supermicro:x12dpi-nt6_firmware:-:*:*:*:*:*:*:* |
| supermicro | x12dpl-i6_firmware | — | cpe:2.3:o:supermicro:x12dpl-i6_firmware:-:*:*:*:*:*:*:* |
| supermicro | x12dpl-nt6_firmware | — | cpe:2.3:o:supermicro:x12dpl-nt6_firmware:-:*:*:*:*:*:*:* |
| supermicro | x12dpt-b6_firmware | — | cpe:2.3:o:supermicro:x12dpt-b6_firmware:-:*:*:*:*:*:*:* |
| supermicro | x12dpt-pt46_firmware | — | cpe:2.3:o:supermicro:x12dpt-pt46_firmware:-:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://blog.freax13.de/cve/cve-2023-35861 | Exploit Third Party Advisory |
| https://www.supermicro.com/en/products/motherboards | Product |
| https://www.supermicro.com/en/support/security_SMTP_Jun_2023 | Vendor Advisory |