Impact
The vulnerability permits arbitrary code execution by an authorized attacker who exploits the SMASH service’s input handling on the BMC firmware. A likely consequence is the ability to alter configuration data or manipulate other critical system parameters. Based on the description, it is inferred that the attacker can execute arbitrary commands, which could result in a crash of the service or cause a denial‑of‑service on the BMC.
Affected Systems
Supermicro X14DBG-DAP and X14DBI server platforms, whose BMC firmware includes the SMASH service. Only these device families are affected as listed by the CNA.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity overall, but the EPSS score of less than 1% suggests that exploitation is currently rare. The vulnerability is not listed in the CISA KEV catalog, so no widespread exploitation is known. The attack vector requires an attacker to be authorized to the BMC, typically through network management or local console, making it a high‑risk event if such access is compromised or granted to an untrusted party.
OpenCVE Enrichment