CVE-2025-8404
BaseFortify
Publication date: 2025-11-18
Last updated on: 2025-11-18
Assigner: Super Micro Computer, Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| supermicro | bmc_shared_library | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-121 | A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function). |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a stack buffer overflow in the Supermicro BMC Shared library. It allows an authenticated attacker with access to the BMC to exploit the stack buffer by sending a specially crafted header, which can lead to arbitrary code execution on the BMC's firmware operating system.
How can this vulnerability impact me? :
The vulnerability can allow an attacker with authenticated access to execute arbitrary code on the BMC's firmware operating system. This could lead to disruption of the BMC's functionality, potential control over the device, and impact on the availability of the system managed by the BMC.