CVE-2025-7623: Supermicro BMC SMASH services has a Stack-based buffer overflow vulnerability
Stack-based buffer overflow in the SMASH-CLP shell. An authenticated attacker with SSH access to the BMC can exploit a stack buffer overflow via a crafted SMASH command, overwrite the return address and registers, and achieve arbitrary code execution on the BMC firmware operating system
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7623?
CVE-2025-7623 is rated as a high severity vulnerability due to the potential for arbitrary code execution.
How do I fix CVE-2025-7623?
To fix CVE-2025-7623, update the firmware of your Supermicro BMC SMASH to the latest version provided by the vendor.
Who is affected by CVE-2025-7623?
CVE-2025-7623 affects authenticated users with SSH access to the Supermicro BMC SMASH shell.
What type of vulnerability is CVE-2025-7623?
CVE-2025-7623 is a stack-based buffer overflow vulnerability.
What can an attacker achieve with CVE-2025-7623?
An authenticated attacker can achieve arbitrary code execution on the BMC's firmware by exploiting CVE-2025-7623.