NVD Vulnerability Detail
Search Exploit, PoC
CVE-2026-3820
Summary

There is a vulnerability in the Supermicro BMC SMTP service at Supermicro AS-2115HS-TNR. 
An attacker may obtain administrator privileges and inject specially crafted characters into the SMTP service configuration. This may cause the underlying system to execute unintended commands during process invocation.

Potential impact includes denial-of-service attacks, arbitrary code execution, or permanent compromise of the controller.

Publication Date June 4, 2026, 6:16 p.m.
Registration Date June 5, 2026, 4:10 a.m.
Last Update June 5, 2026, 1:40 a.m.
CVSS3.1 : HIGH
スコア 7.2
Vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
攻撃元区分(AV) ネットワーク
攻撃条件の複雑さ(AC)
攻撃に必要な特権レベル(PR)
利用者の関与(UI) 不要
影響の想定範囲(S) 変更なし
機密性への影響(C)
完全性への影響(I)
可用性への影響(A)
Related information, measures and tools
Common Vulnerabilities List