Description
Supermicro (SMC) SMASH services contain an Arbitrary code execution issue in X14DBG-DAP and X14DBI.
An authorized attacker can exploit SMASH’s input capability to compromise data integrity or launch a Denial-of-Service (DoS) attack against the BMC.
Published: 2026-07-22
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability permits arbitrary code execution by an authorized attacker who exploits the SMASH service’s input handling on the BMC firmware. A likely consequence is the ability to alter configuration data or manipulate other critical system parameters. Based on the description, it is inferred that the attacker can execute arbitrary commands, which could result in a crash of the service or cause a denial‑of‑service on the BMC.

Affected Systems

Supermicro X14DBG-DAP and X14DBI server platforms, whose BMC firmware includes the SMASH service. Only these device families are affected as listed by the CNA.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity overall, but the EPSS score of less than 1% suggests that exploitation is currently rare. The vulnerability is not listed in the CISA KEV catalog, so no widespread exploitation is known. The attack vector requires an attacker to be authorized to the BMC, typically through network management or local console, making it a high‑risk event if such access is compromised or granted to an untrusted party.

Generated by OpenCVE AI on August 4, 2026 at 15:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the firmware on all X14DBG-DAP and X14DBI devices to the latest release from Supermicro that resolves the SMASH input validation flaw.
  • Restrict BMC management interfaces to a secure, internal network segment, enforce strong authentication, and limit the exposure of the SMASH service to trusted hosts.
  • If the SMASH service is not required, disable it completely or block its port with firewall rules.

Generated by OpenCVE AI on August 4, 2026 at 15:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Smci
Smci x14dbg-dap
Smci x14dbi
Vendors & Products Smci
Smci x14dbg-dap
Smci x14dbi

Wed, 22 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Description Supermicro (SMC) SMASH services contain an Arbitrary code execution issue in X14DBG-DAP and X14DBI. An authorized attacker can exploit SMASH’s input capability to compromise data integrity or launch a Denial-of-Service (DoS) attack against the BMC.
Title Supermicro SMASH service contain an Arbitrary code execution issue
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Supermicro

Published:

Updated: 2026-07-22T12:57:22.874Z

Reserved: 2026-03-09T02:52:17.984Z

Link: CVE-2026-3821

cve-icon Vulnrichment

Updated: 2026-07-22T12:57:19.611Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-22T07:16:35.413

Modified: 2026-07-23T15:33:09.233

Link: CVE-2026-3821

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:00:12Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')