Super Micro Computer, Inc.

First CVE: Feb 4, 2025Active for: 1 year
14
CVEs Published
More CVEs Published than 34% of tracked CNAs
7.0
Avg CVEs / Year
More Avg CVEs / Year than 42% of tracked CNAs
7.0
Avg CVSS Score
Higher Avg CVSS Score than 45% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Super Micro Computer, Inc. as a CNA, 0.0% affect products that Super Micro Computer, Inc. develops as a vendor.

100.0%
Self-reported: 0Third-party: 14

Of all the CVEs published that affect products developed by Super Micro Computer, Inc., 0.0% are self-published by Super Micro Computer, Inc. as a CNA.

100.0%
Self-published: 0Published by other CNAs: 29

Trends Over Time

The number and severity of CVEs published by Super Micro Computer, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 4, 2025
17 months ago
Most Recent CVE
Jul 22, 2026
2 days ago

Top CVEs

All CVEs published by Super Micro Computer, Inc. as a CNA, regardless of affected vendor or product.

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Supermicro (SMC) SMASH services contain an Arbitrary code execution issue in X14DBG-DAP and X14DBI. An authorized attacker can exploit SMASH’s input capability to compromise data i
Jul 22, 20268.838NONO
There is a vulnerability in the Supermicro BMC SMTP service at Supermicro AS-2115HS-TNR.  An attacker may obtain administrator privileges and inject specially crafted characters i
Jun 4, 20267.230NONO
There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X12STW . An attacker can update the system firmware with a specially crafted image.
Sep 19, 20257.228NONO
There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X13SEM-F . An attacker can update the system firmware with a specially crafted image.
Sep 19, 20257.228NONO
There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X13SEM-F . An attacker can update the system firmware with a specially crafted image.
Jan 16, 20268.427NONO
There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X12STW-F . An attacker can update the system firmware with a specially crafted image.
Jan 16, 20267.225NONO
There is a vulnerability in the Supermicro BMC web function at Supermicro MBD-X13SEDW-F. After logging into the BMC Web server, an attacker can use a specially crafted payload to t
Nov 18, 20257.225NONO
There is a vulnerability in the BMC firmware image authentication design at Supermicro MBD-X12DPG-OA6 . An attacker can modify the firmware to bypass BMC inspection and bypass
Feb 4, 20257.223NONO
There is a vulnerability in the Supermicro BMC web function at Supermicro MBD-X13SEDW-F. After logging into the BMC Web server, an attacker can use a specially crafted payload to t
Nov 18, 20257.222NONO
Stack buffer overflow vulnerability exists in the Supermicro BMC Shared library. An authenticated attacker with access to the BMC exploit stack buffer via a crafted  header and ach
Nov 18, 20255.520NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA14 CVEs
Severity distribution among all CVEs352,294 CVEs
MediumHigh
Attack Vector
Local1 (7.1%)
Network13 (92.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None14 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low3 (21.4%)
High10 (71.4%)
None1 (7.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Super Micro Computer, Inc. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Super Micro Computer, Inc. as a CNA — matched by CVE ID, not by organization name.

Top CWEs