CVE-2025-7704 Details
Description
Supermicro BMC Insyde SMASH shell program has a stacked-based overflow vulnerability
A stack-based buffer overflow vulnerability has been identified in the Supermicro BMC Insyde SMASH shell program. This vulnerability allows an attacker to manipulate an environment variable to inject a shell string into the program, leading to program execution corruption. The issue affects select Supermicro motherboards and CMMs.
Affected Supermicro motherboard SKUs will require a BMC update to mitigate this vulnerability. An updated BMC firmware is being tested and validated for affected products. Please check the Supermicro Release Notes for the resolution.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Nov 13, 2025CISA-ADP
Assessed Nov 13, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.supermicro.com/en/support/security_BMC_IPMI_Oct_2025 | Super Micro Computer, Inc. | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-121 | Stack-based Buffer Overflow | Super Micro Computer, Inc. |
Affected Products
| Product | Versions |
|---|---|
| Supermicro BMC | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Super Micro Computer, Inc. |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 13, 2025 | New CVE Received | Super Micro Computer, Inc. |
Volerion