CVE-2013-6785

medium

Description

Directory traversal vulnerability in url_redirect.cgi in Supermicro IPMI before SMT_X9_315 allows authenticated attackers to read arbitrary files via the url_name parameter.

References

https://www.tenable.com/cve/CVE-2013-6785

https://blog.rapid7.com/2013/11/06/supermicro-ipmi-firmware-vulnerabilities/

Details

Source: Mitre, NVD

Published: 2020-01-23

Updated: 2020-02-04

Risk Information

CVSS v2

Base Score: 4

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 4.3

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Severity: Medium