Supermicro BMC
cpe:2.3:a:supermicro:intelligent_platform_management_interface:*:*:*:*:*:*:*, +1 more
A stack-based buffer overflow vulnerability has been identified in the SMASH-CLP shell of Supermicro BMC firmware. This vulnerability allows an authenticated attacker with SSH access to the BMC to exploit a 260-byte stack buffer overflow by sending a crafted SMASH command. The exploitation overwrites the return address and registers, leading to arbitrary code execution on the BMC firmware operating system.
Exploitation of this vulnerability allows for arbitrary code execution on the BMC firmware operating system.
Affected Supermicro motherboard SKUs will require a BMC update to mitigate this vulnerability. An updated BMC firmware has been created and is currently being tested and validated. Please check the Supermicro Release Notes for the resolution.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.