Stack buffer overflow vulnerability exists in the Supermicro BMC Shared library. An authenticated attacker with access to the BMC exploit stack buffer via a crafted  header and achieve arbitrary code execution of the BMC’s firmware operating system.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 19 Nov 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Nov 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Supermicro
Supermicro bmc
Vendors & Products Supermicro
Supermicro bmc

Tue, 18 Nov 2025 08:00:00 +0000

Type Values Removed Values Added
Description Stack buffer overflow vulnerability exists in the Supermicro BMC Shared library. An authenticated attacker with access to the BMC exploit stack buffer via a crafted  header and achieve arbitrary code execution of the BMC’s firmware operating system.
Title Stack buffer overflow vulnerability exists in the Supermicro BMC Shared library
Weaknesses CWE-121
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Supermicro

Published:

Updated: 2025-11-19T16:49:08.007Z

Reserved: 2025-07-31T03:32:10.733Z

Link: CVE-2025-8404

cve-icon Vulnrichment

Updated: 2025-11-18T15:03:02.505Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-18T08:15:51.783

Modified: 2025-11-18T14:06:29.817

Link: CVE-2025-8404

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-11-19T10:48:01Z

Weaknesses