ADVERTISEMENT
Bizmo Arena
No Result
View All Result
  • Review
  • Apple
  • Applications
  • Computers
  • Gaming
  • Gear
    • Audio
    • Camera
    • Smartphone
  • Microsoft
  • Photography
  • Security
  • Advertise With Us
BizmoArena
No Result
View All Result
BizmoArena
No Result
View All Result
ADVERTISEMENT
ADVERTISEMENT

Home » Supermicro BMC Firmware Bugs Let Attackers Evade Root of Trust

Supermicro BMC Firmware Bugs Let Attackers Evade Root of Trust

Joel Wamono by Joel Wamono
September 24, 2025
Supermicro BMC Firmware Bugs Let Attackers Evade Root of Trust
ADVERTISEMENT
Share on FacebookShare on Twitter

Two new Supermicro BMC Firmware Bugs have been disclosed, allowing attackers to bypass essential security mechanisms and install malicious firmware on affected systems. The vulnerabilities, impacting Supermicro’s Baseboard Management Controller (BMC) firmware, weaken critical verification steps used to secure the firmware update process.

ADVERTISEMENT

Cybersecurity firm Binarly, which discovered and reported the vulnerabilities, explained that these flaws occur due to improper verification of cryptographic signatures during firmware updates. The two flaws are listed as:

  • CVE-2025-7937 (CVSS score: 6.6): Allows attackers to bypass BMC firmware verification by redirecting the program to a fake “fwmap” table in the unsigned region.
  • CVE-2025-6198 (CVSS score: 6.4): Enables attackers to bypass the signing table verification process by redirecting to a fake signing table (“sig_table”) in the unsigned region.

How the vulnerabilities work

Firmware updates on Supermicro BMC systems involve three steps:

ADVERTISEMENT
  1. Retrieving the public key from the BMC SPI flash chip.
  2. Processing the “fwmap” or “sig_table” table embedded in the uploaded image.
  3. Computing a cryptographic hash digest of signed firmware regions and verifying the signature against the calculated hash digest.

Both vulnerabilities exploit weaknesses in these steps. CVE-2025-7937 allows a crafted firmware image to bypass the BMC verification logic, redirecting the system to a fake “fwmap” table. Similarly, CVE-2025-6198 manipulates the “sig_table” to bypass signing checks and install malicious firmware.

Root of Trust bypass

The flaws undermine the Root of Trust (RoT), a fundamental security feature designed to ensure firmware integrity. Previously, Supermicro’s PSIRT (Product Security Incident Response Team) claimed that the hardware RoT would prevent these issues. However, further research by Binarly found that CVE-2025-6198 indeed bypasses this security feature.

Alex Matrosov, CEO of Binarly, warned that reusing signing keys across product lines could have a massive impact if they were to leak. The CVE-2025-6198 vulnerability, in particular, shows how significant the consequences could be if an attacker gains access to the signing keys.

Implications for firmware security

These vulnerabilities reflect a broader issue in firmware security. Both flaws allow attackers to install specially crafted firmware images without triggering the usual security safeguards. Given the potential severity of these bugs, CVE-2025-7937 and CVE-2025-6198 are medium-severity vulnerabilities, but they still pose a serious threat to Supermicro’s customer base.

ADVERTISEMENT

Binarly also highlighted previous issues with Supermicro’s firmware, such as the CVE-2024-10237 vulnerability, which similarly involved bypassing the firmware validation process. These vulnerabilities demonstrate the ongoing challenge of maintaining secure firmware in modern systems, especially when dealing with complex security features like RoT.

Conclusion

Supermicro must address these firmware flaws quickly to prevent potential exploitation. The Supermicro BMC Firmware Bugs show that even the most advanced security features, like the Root of Trust, can be bypassed if proper cryptographic checks are not in place. As security research continues to uncover weaknesses in system firmware, it’s clear that manufacturers need to strengthen their update and verification protocols to avoid the risks posed by such vulnerabilities.

Tags: CVE-2025firmware securityfirmware vulnerabilitiesroot of trustSupermicro BMC Firmware Bugs
ADVERTISEMENT
Joel Wamono

Joel Wamono

RelatedPosts

Metal Fetishist Firmware v2.0 Released
Firmware Updates

Metal Fetishist Firmware v2.0 Released

September 15, 2025
Canon C400 Open Gate Firmware: Features & Release
Camera

Canon C400 Open Gate Firmware: Features & Release

September 10, 2025
Nvidia Must Prove Chip Security to Regain China’s Trust
AI

Nvidia Must Prove Chip Security to Regain China’s Trust

August 4, 2025
watchOS 11.5 Update: Pride Face and Apple TV Features
Apple

watchOS 11.5 Update: Pride Face and Apple TV Features

May 13, 2025
Next Post
Vivo Origin OS 6: Launching with Android 16 for Smartphones

Vivo Origin OS 6: Launching with Android 16 for Smartphones

Amazon Best Seller

ADVERTISEMENT

Recommended.

Samsung has unveiled the Galaxy Tab S10+

Samsung has unveiled the Galaxy Tab S10+

September 26, 2024
Realme 14T leaks: 5G, IP69K durability, 100W fast charging

Realme 14T leaks: 5G, IP69K durability, 100W fast charging

March 22, 2025

Trending.

Lovense Solace Pro CEE

Lovense’s AI-Powered Solace Pro Debuts at CEE 2025

May 19, 2025
Honor Pad X9a Official with 11.5″ Display, 8,300mAh Battery

Honor Pad X9a Official with 11.5″ Display, 8,300mAh Battery

March 22, 2025
Microsoft Sentinel: Agentic Security Platform for AI Defense

Microsoft Sentinel: Agentic Security Platform for AI Defense

September 30, 2025
Acer Liquid Z6 Plus Full Phone Specifications

Acer Liquid Z6 Plus Full Phone Specifications

September 21, 2025
Huawei Nova 12i Review: A Mid-Range Contender with a Stunning 108MP Camera

Huawei Nova 12i Review: A Mid-Range Contender with a Stunning 108MP Camera

September 15, 2024
ADVERTISEMENT
  • About Us
  • Privacy
  • Contact
  • Terms
  • Advertise

BizmoArena is part of the Bizmart Holdings publishing family. © 2025 Bizmart Holdings LLC. All rights reserved.

No Result
View All Result
  • Review
  • Apple
  • Applications
  • Computers
  • Gaming
  • Gear
    • Audio
    • Camera
    • Smartphone
  • Microsoft
  • Photography
  • Security
  • Advertise With Us

BizmoArena is part of the Bizmart Holdings publishing family. © 2025 Bizmart Holdings LLC. All rights reserved.