Supermicro BMC Firmware Vulnerabilities Allow Firmware Tampering
Summary
Hide β²
Show βΌ
Two new vulnerabilities in Supermicro Baseboard Management Controller (BMC) firmware allow attackers to bypass verification steps and update the system with malicious firmware. The flaws, CVE-2025-7937 and CVE-2025-6198, exploit weaknesses in the firmware verification logic to evade the Root of Trust (RoT) security feature. These vulnerabilities could enable attackers to gain persistent control over the BMC system and the main server OS. The issues were discovered by Binarly and affect multiple Supermicro products. The vulnerabilities stem from improper verification of cryptographic signatures, allowing attackers to redirect the firmware update process to fake tables and load malicious images.
Timeline
-
23.09.2025 21:00 π° 1 articles Β· β± 21h ago
Two New Supermicro BMC Firmware Vulnerabilities Disclosed
Two new vulnerabilities in Supermicro BMC firmware, CVE-2025-7937 and CVE-2025-6198, have been disclosed. These flaws allow attackers to bypass the firmware verification logic and update the system with malicious firmware, potentially gaining persistent control over the BMC system and the main server OS. The vulnerabilities were discovered by Binarly and affect multiple Supermicro products. CVE-2025-7937 is a bypass for CVE-2024-10237, which was disclosed earlier. The flaws exploit weaknesses in the firmware verification logic to evade the Root of Trust (RoT) security feature.
Show sources
- Two New Supermicro BMC Bugs Allow Malicious Firmware to Evade Root of Trust Security β thehackernews.com β 23.09.2025 21:00
Information Snippets
-
CVE-2025-7937 allows attackers to bypass the Supermicro BMC firmware verification logic of Root of Trust (RoT) 1.0 by redirecting to a fake 'fwmap' table.
First reported: 23.09.2025 21:00π° 1 source, 1 articleShow sources
- Two New Supermicro BMC Bugs Allow Malicious Firmware to Evade Root of Trust Security β thehackernews.com β 23.09.2025 21:00
-
CVE-2025-6198 allows attackers to bypass the Supermicro BMC firmware verification logic of the Signing Table by redirecting to a fake 'sig_table'.
First reported: 23.09.2025 21:00π° 1 source, 1 articleShow sources
- Two New Supermicro BMC Bugs Allow Malicious Firmware to Evade Root of Trust Security β thehackernews.com β 23.09.2025 21:00
-
The vulnerabilities enable attackers to update the system firmware with a malicious image, potentially gaining persistent control over the BMC system and the main server OS.
First reported: 23.09.2025 21:00π° 1 source, 1 articleShow sources
- Two New Supermicro BMC Bugs Allow Malicious Firmware to Evade Root of Trust Security β thehackernews.com β 23.09.2025 21:00
-
The flaws were discovered by Binarly and affect multiple Supermicro products.
First reported: 23.09.2025 21:00π° 1 source, 1 articleShow sources
- Two New Supermicro BMC Bugs Allow Malicious Firmware to Evade Root of Trust Security β thehackernews.com β 23.09.2025 21:00
-
CVE-2025-7937 is a bypass for CVE-2024-10237, which was disclosed by Supermicro in January 2025.
First reported: 23.09.2025 21:00π° 1 source, 1 articleShow sources
- Two New Supermicro BMC Bugs Allow Malicious Firmware to Evade Root of Trust Security β thehackernews.com β 23.09.2025 21:00
-
CVE-2024-10237 is a logical flaw in the validation process of the uploaded firmware, allowing attackers to reflash the BMC SPI chip with a malicious image.
First reported: 23.09.2025 21:00π° 1 source, 1 articleShow sources
- Two New Supermicro BMC Bugs Allow Malicious Firmware to Evade Root of Trust Security β thehackernews.com β 23.09.2025 21:00
-
CVE-2024-10238 and CVE-2024-10239 are stack overflow flaws in the firmware's image verification function, allowing arbitrary code execution in the BMC context.
First reported: 23.09.2025 21:00π° 1 source, 1 articleShow sources
- Two New Supermicro BMC Bugs Allow Malicious Firmware to Evade Root of Trust Security β thehackernews.com β 23.09.2025 21:00
-
The fix for CVE-2024-10237 was found to be insufficient, allowing attackers to insert a custom 'fwmap' table and run custom code in the BMC context.
First reported: 23.09.2025 21:00π° 1 source, 1 articleShow sources
- Two New Supermicro BMC Bugs Allow Malicious Firmware to Evade Root of Trust Security β thehackernews.com β 23.09.2025 21:00
-
CVE-2025-6198 bypasses the BMC RoT security feature, allowing attackers to load a malicious image without modifying the hash digest value.
First reported: 23.09.2025 21:00π° 1 source, 1 articleShow sources
- Two New Supermicro BMC Bugs Allow Malicious Firmware to Evade Root of Trust Security β thehackernews.com β 23.09.2025 21:00