Endpoint Security

Patch Bypassed for Supermicro Vulnerability Allowing BMC Hack

Binarly researchers have found a way to bypass a patch for a previously disclosed vulnerability. 

Motherboard vulnerability

Supermicro has patched two BMC vulnerabilities that can be exploited to perform malicious firmware updates on impacted devices.

According to firmware security company Binarly, one of these security holes is the result of a previously issued patch being bypassed. 

The BMC (Baseboard Management Controller), a specialized chip typically present on the motherboard of servers and high-end computers, provides out-of-band management capabilities that allow administrators to remotely monitor and manage the device, even if the operating system is down or the power is off.

Supermicro informed customers in January that a researcher from Nvidia had discovered several BMC firmware vulnerabilities, including CVE-2024-10237, an image authentication issue that could allow an attacker to conduct malicious firmware updates.

“An attacker can modify the firmware to bypass BMC inspection and bypass the signature verification process,” Supermicro explained.

A malicious firmware update would enable the attacker to gain complete and persistent control of the BMC and the operating system. 

Advertisement. Scroll to continue reading.

Binarly analyzed CVE-2024-10237 and discovered that the patch released by Supermicro could be bypassed. As a result, the vendor assigned a new CVE identifier, CVE-2025-7937, and this month made another attempt to patch it

During its investigation, Binarly also found another similar vulnerability, which has been assigned the CVE identifier CVE-2025-6198.

The cybersecurity firm warned that CVE-2025-6198 can be exploited not only to deploy a malicious firmware image, but also to bypass the Root of Trust (RoT) security feature, which ensures the integrity and authenticity of the BMC firmware. 

Supermicro has patched this vulnerability as well with its latest updates, and noted that there is no evidence of in-the-wild exploitation for either of the flaws.

“These findings matter because they show how fragile firmware validation can be, even with supposed hardware-backed security,” Alex Matrosov, CEO and head of research at Binarly, told SecurityWeek

“Keep in mind, successful exploits for these vulnerabilities give attackers persistent code execution at the BMC level and control of both the Base Management Controller and the main OS. This presents significant risk to enterprise organizations,” Matrosov added.

Binarly has published a video showing the exploit in action:

BMC vulnerabilities being exploited in malicious attacks is not unheard of. CISA warned recently that an AMI BMC flaw allowing attackers to take control of the target machine has been exploited in attacks. 

Related: Critical AMI BMC Vulnerability Exposes Servers to Disruption, Takeover

Related: Flaw in Industrial Computer Maker’s UEFI Apps Enables Secure Boot Bypass on Many Devices

Related: Palo Alto Networks Addresses Impact of BIOS, Bootloader Vulnerabilities on Its Firewalls

Related Content

Vulnerabilities

A Chinese threat actor has exploited the bug to exfiltrate sensitive information from nearly 1,000 ZyXEL switches.

Vulnerabilities

The bug lets attackers automatically install and preview themes and could lead to remote code execution.

Vulnerabilities

Attackers could exploit the flaws to cause denial-of-service conditions, disclose memory, or modify memory.

Artificial Intelligence

Hacktron researchers earned a bug bounty after demonstrating access to OpenAI employee accounts. 

Artificial Intelligence

Microsoft fixed vulnerabilities across Azure and AI-branded products, with privilege escalation flaws accounting for the majority.

Vulnerabilities

CVE-2026-58138 is an unauthenticated remote code execution vulnerability that attackers can exploit via inline workflow definitions.

Endpoint Security

Check Point Security Management and Log Servers are affected by a critical vulnerability that can allow remote code execution with root privileges.

Government

The decision follows BOD 26-04, which directs federal organizations to prioritize vulnerabilities based on real-world risk.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version