CVE-2025-8404 Details
Description
Stack buffer overflow vulnerability exists in the Supermicro BMC Shared library. An authenticated attacker with access to the BMC exploit stack buffer via a crafted header and achieve arbitrary code execution of the BMC’s firmware operating system.
A stack-based buffer overflow vulnerability has been identified in the Supermicro BMC Shared library. This vulnerability allows an authenticated attacker with access to the BMC to overflow a 128-byte stack buffer by sending a crafted Content-Type HTTP header. Exploitation of this vulnerability could lead to arbitrary code execution within the BMC's firmware operating system.
Affected Supermicro motherboard SKUs will require a BMC update to mitigate this vulnerability. An updated BMC firmware has been created and is currently being tested and validated. Please check the Supermicro Release Notes for the resolution.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Nov 18, 2025CISA-ADP
Assessed Nov 18, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.supermicro.com/zh_tw/support/security_BMC_IPMI_Nov_2025 | Super Micro Computer, Inc. | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-121 | Stack-based Buffer Overflow | Super Micro Computer, Inc. |
Affected Products
| Product | Versions |
|---|---|
| Supermicro BMC | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Super Micro Computer, Inc. |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 18, 2025 | New CVE Received | Super Micro Computer, Inc. |
Volerion