CVE-2026-3820
Severity CVSS v4.0:
Pending analysis
Type:
CWE-78
OS Command Injections
Publication date:
04/06/2026
Last modified:
22/07/2026
Description
There is a vulnerability in the Supermicro BMC SMTP service at Supermicro AS-2115HS-TNR. <br />
An attacker may obtain administrator privileges and inject specially crafted characters into the SMTP service configuration. This may cause the underlying system to execute unintended commands during process invocation.<br />
<br />
Potential impact includes denial-of-service attacks, arbitrary code execution, or permanent compromise of the controller.
Impact
Base Score 3.x
7.20
Severity 3.x
HIGH



