CVE-2026-3820
Gravedad CVSS v3.1:
ALTA
Tipo:
CWE-78
Neutralización incorrecta de elementos especiales usados en un comando de sistema operativo (Inyección de comando de sistema operativo)
Fecha de publicación:
04/06/2026
Última modificación:
04/06/2026
Descripción
*** Pendiente de traducción *** There is a vulnerability in the Supermicro BMC SMTP service at Supermicro AS-2115HS-TNR. <br />
An attacker may obtain administrator privileges and inject specially crafted characters into the SMTP service configuration. This may cause the underlying system to execute unintended commands during process invocation.<br />
<br />
Potential impact includes denial-of-service attacks, arbitrary code execution, or permanent compromise of the controller.
Impacto
Puntuación base 3.x
7.20
Gravedad 3.x
ALTA



