Supermicro BMC SMASH services has a Stack-based buffer overflow vulnerability
Vulnerability Description
Stack-based buffer overflow in the SMASH-CLP shell. An authenticated attacker with SSH access to the BMC can exploit a stack buffer overflow via a crafted SMASH command, overwrite the return address and registers, and achieve arbitrary code execution on the BMC firmware operating system
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-7623
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Coreweave Red Team and Hoang Bui from Coreweave
More from SMCI
View All →Affected Vendor
SMCI
View all reports →