Monday, 12 Jan 2026
Subscribe
logo
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Font ResizerAa
Data Center NewsData Center News
Search
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Data Center News > Blog > Global Market > New Supermicro BMC vulnerabilities open servers to malicious attacks on firmware
Global Market

New Supermicro BMC vulnerabilities open servers to malicious attacks on firmware

Last updated: September 26, 2025 12:24 am
Published September 26, 2025
Share
Photo of Out of Focus IT Technician Turning on Data Server.
SHARE

Throughout this analysis, Binarly found a second vulnerability, CVE-2025-6198, regarding Supermicro’s X13SEM-F motherboard firmware, additionally rated as excessive severity with a CVSS rating of seven.2.

Whereas CVE-2025-7937 or CVE-2025-6198 would pose main safety dangers within the occasion attackers had been capable of exploit them, the caveat is that to take action the attackers would want to have established admin entry to the methods to work together with the firmware.

Which may make exploitation sound like a protracted shot — neither might be exploited remotely — however as numerous real-world assaults present, rogue admin entry and privilege elevation might be gained in a separate, oblique assault.

Incomplete repair

CVE-2025-7937 and CVE-2025-6198 uncovered totally different points with Supermicro’s validation logic, the checking course of that’s speculated to cease respectable firmware being changed with malicious code.

Binarly mentioned that the January flaw, CVE-2024-10237, made it potential to idiot the validation course of by including illicit entries to the firmware map desk (fwmap) in order that the rogue firmware matched the cryptographically signed worth.

Supermicro adjusted the validation checks to detect this, however via CVE-2025-7937, Binarly researchers had been capable of re-target the modified validation checking.

Source link

See also  DDoS Attacks: Data Centers Caught in the Crosshairs | DCN
TAGGED: Attacks, BMC, firmware, malicious, Open, Servers, Supermicro, vulnerabilities
Share This Article
Twitter Email Copy Link Print
Previous Article UK’s Nscale Raises $1.1B in AI Data Center Frenzy UK’s Nscale Raises $1.1B in AI Data Center Frenzy
Next Article Data Centers Face Critical Balancing Act As Grid Ages Data Centers Face Critical Balancing Act As Grid Ages
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Your Trusted Source for Accurate and Timely Updates!

Our commitment to accuracy, impartiality, and delivering breaking news as it happens has earned us the trust of a vast audience. Stay ahead with real-time updates on the latest events, trends.
FacebookLike
TwitterFollow
InstagramFollow
YoutubeSubscribe
LinkedInFollow
MediumFollow
- Advertisement -
Ad image

Popular Posts

Securing Edge Data Centers: Challenges and Solutions | DCN

Securing any kind of knowledge middle is difficult sufficient given the big range of threats…

April 18, 2024

Magnetic jamming opens new frontiers for microrobotics

From Stiff to Tender in a Snap: Magnetic Jamming Opens New Frontiers for Microrobotics. Credit…

October 18, 2025

Battery-like computer memory keeps working above 1,000°F

The reminiscence units fabricated utilizing tantalum oxide on this chip can retailer knowledge for each…

December 9, 2024

The tech REIT behind the cloud boom

The infrastructure supporting knowledge holds vital significance in our digital panorama. Among the many key…

March 13, 2024

Halogen-free plasma technique achieves atomic-level etching of hafnium oxide for next-gen semiconductors

A facile anisotropic atomic-layer etching course of for HfO2 movies at room temperature with out…

September 10, 2025

You Might Also Like

Engineer
Global Market

AI, edge, and security: Shaping the need for modern infrastructure management

By saad
AWS logo on wall
Global Market

AWS hikes prices for EC2 Capacity Blocks amid soaring GPU demand

By saad
Portrait of Two Diverse Developers Working on Computers, Typing Lines of Code that Appear on Big Screens Surrounding Them. Male and Female Programmers Creating Innovative Software, Fixing Bugs.
Global Market

At CES, Nvidia launches Vera Rubin platform for AI data centers

By saad
Middle Aged Bearded Senior Project Manager Stands Next to Big Screen with Neural Network. Professional Computer Data Science Engineer Work in a System Control and Monitoring Telecommunications Office
Global Market

Ethernet groups keep 2026 focus on higher bandwidth, AI demands

By saad
Data Center News
Facebook Twitter Youtube Instagram Linkedin

About US

Data Center News: Stay informed on the pulse of data centers. Latest updates, tech trends, and industry insights—all in one place. Elevate your data infrastructure knowledge.

Top Categories
  • Global Market
  • Infrastructure
  • Innovations
  • Investments
Usefull Links
  • Home
  • Contact
  • Privacy Policy
  • Terms & Conditions

© 2024 – datacenternews.tech – All rights reserved

Welcome Back!

Sign in to your account

Lost your password?
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.
You can revoke your consent any time using the Revoke consent button.