Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-95mg-3279-c5xh

Опубликовано: 18 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

Stack-based buffer overflow in the SMASH-CLP shell. An authenticated attacker with SSH access to the BMC can exploit a stack buffer overflow via a crafted SMASH command, overwrite the return address and registers, and achieve arbitrary code execution on the BMC firmware operating system

Stack-based buffer overflow in the SMASH-CLP shell. An authenticated attacker with SSH access to the BMC can exploit a stack buffer overflow via a crafted SMASH command, overwrite the return address and registers, and achieve arbitrary code execution on the BMC firmware operating system

EPSS

Процентиль: 23%
0.00075
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-121

Связанные уязвимости

CVSS3: 5.4
nvd
3 месяца назад

Stack-based buffer overflow in the SMASH-CLP shell. An authenticated attacker with SSH access to the BMC can exploit a stack buffer overflow via a crafted SMASH command, overwrite the return address and registers, and achieve arbitrary code execution on the BMC firmware operating system

EPSS

Процентиль: 23%
0.00075
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-121