Database/Firmware, BMC & network fabric
Supermicro BMC: stack-based buffer overflow in the Insyde SMASH shell
Impact
The SMASH CLP shell reachable on the Supermicro BMC has a stack-based overflow. A BMC is the out-of-band root of a server: whoever controls it controls power, boot media, console and firmware for the node, so memory corruption in a shell that BMC users can reach is worth treating seriously on a GPU node that hosts other tenants' workloads. The NVD record is one sentence and does not state whether the overflow is exploitable for code execution or only crashes the service - the vendor's score reflects a limited integrity and availability impact, not full BMC takeover, and the entry stays at that. Confirmed on SYS-111C-NR in the Supermicro October 2025 BMC/IPMI advisory.
Who can reach it
A network-reachable, authenticated BMC user - in practice anyone on the management VLAN who holds BMC credentials. Authentication is required (vendor vector PR:L).
What to do
Apply the BMC firmware update from the Supermicro October 2025 BMC/IPMI security page for the affected platform. BMC firmware can usually be flashed without halting the host OS, but plan for the BMC itself to go away during the update - no out-of-band console or power control while it reboots - and verify afterwards. Independently, the management network should not be reachable from tenant or general corporate networks; that containment is what limits this class of bug. The record does not name a fixed firmware version.
References
Related entries
- Dell OMSA: CSRF in the server management web interface can lead to remote executionCVE-2026-80355 · Dell OpenManage Server Administrator (OMSA web interface)Medium
- AMD Platform Security Processor - SEV key derivation (PSP firmware <= 0.17 build 11): The SEV implementation in PSPCVE-2019-9836 · AMD Platform Security Processor - SEV key derivation (PSP firmware <= 0.17 build 11)Medium
- HPE iLO 4 / iLO 5 (unauthenticated information disclosure): An unauthenticated remote request pulls back the serverCVE-2020-7202 · HPE iLO 4 / iLO 5 (unauthenticated information disclosure)Medium
- APC/Schneider Electric UPS, PDU, and cooling products using NMC2/NMC3 (Smart-UPS, Symmetra, Galaxy, rack PDUs, InRowCVE-2021-22815 · APC/Schneider Electric UPS, PDU, and cooling products using NMC2/NMC3Medium
- AMI MegaRAC SPx 12 / SPx 13 (BMC login): The login flow answers differently for real and fake usernames, soCVE-2021-45925 · AMI MegaRAC SPx 12 / SPx 13 (BMC login)Medium
- AMI MegaRAC: Weak MD5 password hashing for BMC accountsCVE-2022-40258 · AMI MegaRACMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.