Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Samsung fans won’t like this: OnePlus beats the S25 Ultra in many ways

    November 16, 2025

    Walmart will sell you this $89 LG UltraGear monitor for a limited time — but it won’t last

    November 16, 2025

    A week with this Ora Ring competitor took the edge off my excitement – ​​here’s how things went

    November 16, 2025
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»New Supermacro BMC weaknesses open server for malicious attacks on firmware
    Security

    New Supermacro BMC weaknesses open server for malicious attacks on firmware

    PineapplesUpdateBy PineapplesUpdateSeptember 25, 2025No Comments1 Min Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    New Supermacro BMC weaknesses open server for malicious attacks on firmware
    Share
    Facebook Twitter LinkedIn Pinterest Email


    New Supermacro BMC weaknesses open server for malicious attacks on firmware

    During this research, Binralli discovered another vulnerability, Cve-2025-6198Related to the X13SEM-F motherboard firmware of the supermichro, also evaluated as a high severity with a CVSS score of 7.2.

    While the CVE-2025-7937 or CVE-2025-6198 event will pose a major security risk, the attackers were able to exploit them, the cavet is that the attackers would need an administrator access to the attackers to do so.

    It can create a sound of exploitation like a long shot-can only be exploited from far away-but as shows of countless real-world attacks, evil administrators and privileges can be obtained in a different, indirect attack.

    Incomplete fix

    CVE-2025-7937 and CVE-2025-6198 highlighted different issues with verification logic of Supermacro, checking process that valid firmware are being replaced with malicious code.

    Binarly said that the January defect, CVE-2024-10237, made it possible to fool the verification process by adding illegal entries to the firmware map table (FWMAP) to fool the verification process so that the evil firmware matched the cryptographic price signed.

    Supermichro adjusted the verification check to detect this, but through CVE -2025–7937, binomed researchers were able to renew the revised verification checking.

    attacks BMC firmware malicious open server Supermacro weaknesses
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleMithun now explains why your sheets formula failed
    Next Article Microcidients promote semiconductor workforce skills
    PineapplesUpdate
    • Website

    Related Posts

    AI/ML

    Meta researchers open LLM black box to improve flawed AI reasoning

    October 31, 2025
    AI/ML

    IBM’s open source Granite 4.0 Nano AI models are small enough to run locally, right in your browser

    October 29, 2025
    Startups

    Europe’s plan to overtake US tech giants is built on open source – and it’s taking hold

    October 20, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    10,000 steps or Japanese walk? We ask experts if you should walk ahead or fast

    June 16, 20250 Views

    FIFA Club World Cup Soccer: Stream Palmirus vs. Porto lives from anywhere

    June 16, 20250 Views

    What do chatbott is careful about punctuation? I tested it with chat, Gemini and Cloud

    June 16, 20250 Views
    Our Picks

    Samsung fans won’t like this: OnePlus beats the S25 Ultra in many ways

    November 16, 2025

    Walmart will sell you this $89 LG UltraGear monitor for a limited time — but it won’t last

    November 16, 2025

    A week with this Ora Ring competitor took the edge off my excitement – ​​here’s how things went

    November 16, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2025 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.