Database/Firmware, BMC & network fabric
Supermicro BMC virtual media (H11/H12/M11/X9/X10/X11): Virtual media service uses weak/absent encryption
CVE-2019-16649Firmware, BMC & network fabriccurated
Impact
Virtual media service uses weak/absent encryption and authentication — credential capture and attaching an arbitrary virtual USB device to the host, i.e. arbitrary boot media
Who can reach it
Network, unauthenticated
What to do
BMC firmware update across every affected generation; interim control is blocking the virtual-media ports (623/5900/5901) at the management-network boundary
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.