Supermicro BMC
cpe:2.3:a:supermicro:intelligent_platform_management_interface:*:*:*:*:*:*:*, +1 more
A stack-based buffer overflow vulnerability has been identified in the Supermicro BMC Insyde SMASH shell program. This vulnerability allows an attacker to manipulate an environment variable to inject a shell string into the program, leading to program execution corruption. The issue affects select Supermicro motherboards and CMMs.
Exploitation of this vulnerability could allow for a stack-based buffer overflow, potentially leading to arbitrary code execution by overwriting the return address on the stack.
Affected Supermicro motherboard SKUs will require a BMC update to mitigate this vulnerability. An updated BMC firmware is being tested and validated for affected products. Please check the Supermicro Release Notes for the resolution.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.