Supermicro BMC Firmware Authentication Vulnerability on MBD-X12DPG-OA6

Vulnerability

A vulnerability exists in the BMC firmware image authentication process on Supermicro MBD-X12DPG-OA6 motherboards. This issue allows an attacker to modify the firmware, bypassing BMC inspection and the signature verification process. The vulnerability is part of a broader set of issues affecting various Supermicro motherboards, all of which will require a BMC update to address the vulnerabilities.

Impact

Exploitation of this vulnerability could lead to unauthorized firmware modifications, allowing attackers to bypass security checks and potentially introduce malicious code or alter system behavior.

Remediation

An updated BMC firmware is available to address this vulnerability. Affected users should consult the Supermicro Release Notes for the update. As an immediate measure, it is recommended to follow the BMC Configuration Best Practices Guide to reduce the attack surface.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
1.4
impact
2.5
exploitability
4.4
remediation
8.3
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.