Supermicro BMC
cpe:2.3:a:supermicro:intelligent_platform_management_interface:*:*:*:*:*:*:*, +1 more
A stack-based buffer overflow vulnerability has been identified in the Supermicro BMC Shared library. This vulnerability allows an authenticated attacker with access to the BMC to overflow a 128-byte stack buffer by sending a crafted Content-Type HTTP header. Exploitation of this vulnerability could lead to arbitrary code execution within the BMC's firmware operating system.
Exploitation of this vulnerability could result in unauthorized arbitrary code execution on the BMC's firmware operating system.
Affected Supermicro motherboard SKUs will require a BMC update to mitigate this vulnerability. An updated BMC firmware has been created and is currently being tested and validated. Please check the Supermicro Release Notes for the resolution.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.