Database/Firmware, BMC & network fabric
Supermicro BMC SMASH-CLP shell on MBD-X13SEDW-F: Full control of the instruction pointer inside the BMC's firmware OS
Impact
Full control of the instruction pointer inside the BMC's firmware OS from a shell that operators routinely hand to junior staff and monitoring tooling. The attacker converts a limited management login into arbitrary code on the controller, and from there into the standard BMC prize set: power control, console capture, virtual media, and firmware-level persistence. The published CVSS understates this - the vector was scored conservatively, but the described primitive is return-address control. A stack buffer overflow reached by a crafted SMASH command, with control of the saved return address and registers.
Who can reach it
An authenticated low-privilege BMC account with SSH access to the controller. Any operator-tier credential works; no administrator role is needed.
What to do
Firmware flash from Supermicro's November 2025 BMC/IPMI advisory batch, matched to the board SKU. The cheap and immediate mitigation is config-only: turn off SSH/SMASH on the BMC if your management path is Redfish or IPMI-over-LAN. That single change also covers CVE-2026-3821 and the rest of the SMASH overflow cluster, so it is the highest-leverage action available before a flash window opens.
References
Related entries
- AMD Platform Security Processor - SEV key derivation (PSP firmware <= 0.17 build 11): The SEV implementation in PSPCVE-2019-9836 · AMD Platform Security Processor - SEV key derivation (PSP firmware <= 0.17 build 11)Medium
- HPE iLO 4 / iLO 5 (unauthenticated information disclosure): An unauthenticated remote request pulls back the serverCVE-2020-7202 · HPE iLO 4 / iLO 5 (unauthenticated information disclosure)Medium
- APC/Schneider Electric UPS, PDU, and cooling products using NMC2/NMC3 (Smart-UPS, Symmetra, Galaxy, rack PDUs, InRowCVE-2021-22815 · APC/Schneider Electric UPS, PDU, and cooling products using NMC2/NMC3Medium
- AMI MegaRAC SPx 12 / SPx 13 (BMC login): The login flow answers differently for real and fake usernames, soCVE-2021-45925 · AMI MegaRAC SPx 12 / SPx 13 (BMC login)Medium
- AMI MegaRAC: Weak MD5 password hashing for BMC accountsCVE-2022-40258 · AMI MegaRACMedium
- AMD IOMMU - nested page table entry faults bypass SEV-SNP RMP checks: The IOMMU mishandles invalid nested page tableCVE-2023-20582 · AMD IOMMU - nested page table entry faults bypass SEV-SNP RMP checksMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.