Database/Firmware, BMC & network fabric
Supermicro BMC firmware validation (MBD-X12DPG-OA6): Root-of-Trust bypass
Impact
Root-of-Trust bypass — firmware image authentication design flaw lets a modified image pass BMC inspection and signature verification. Persistent below-OS implant
Who can reach it
Network, high-privilege BMC access
What to do
BMC flash with a fixed Supermicro build; the RoT bypass means prior firmware state cannot be trusted, so treat affected nodes as requiring re-attestation, not just patching
Fleet impact
How widespread
very common - Supermicro is a dominant GPU-server ODM for neoclouds
Cost to remediate
firmware-flash + RoT re-provisioning - the flaw is in the update-validation path itself, so a compromised node may need physical-access recovery of the SPI/BMC flash
Why it hits the whole fleet
A signed-firmware-validation bypass means the fleet's defense against malicious firmware is itself the bug: an attacker can push a persistent BMC implant that survives host reinstall and is invisible to the OS.
References
Related entries
- Supermicro BMC firmware image verification routine on MBD-X12DPG-OA6: A crafted update image smashes the stackCVE-2024-10238 · Supermicro BMC firmware image verification routine on MBD-X12DPG-OA6High
- Supermicro OpenBMC firmware image verification (MBD-X12DPG-OA6), fat->fsd.max_fld field: The BMC's own firmware-imageCVE-2024-10239 · Supermicro OpenBMC firmware image verification (MBD-X12DPG-OA6), fat->fsd.max_fld fieldHigh
- Intel Xeon memory controller configuration (with SGX): Incorrect default permissions on Xeon memory controllerCVE-2024-21820 · Intel Xeon memory controller configuration (with SGX)High
- Intel Server D50DNP UEFI firmware (PlatformVariableInitDxe): Improper input validation in a UEFI DXE driver on IntelCVE-2024-22095 · Intel Server D50DNP UEFI firmware (PlatformVariableInitDxe)High
- Dell PowerEdge Server BIOS (heap-based buffer overflow): A high-privileged local attacker writes to memory it shouldCVE-2024-22453 · Dell PowerEdge Server BIOS (heap-based buffer overflow)High
- Lenovo XClarity Controller (XCC) - IPMI command handler: A specially crafted IPMI command gives an authenticated XCCCVE-2024-38509 · Lenovo XClarity Controller (XCC) - IPMI command handlerHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.