Get a Pentest and security assessment of your IT network.

News

Flaw in update process for BMCs in Supermicro servers allows to deliver persistent malware or brick the server

A team of security researchers discovered a vulnerability in the baseboard management controller (BMC) hardware used by Supermicro servers. The update mechanism doesnt implement a code signing verification mechanism to check if the firmware is downloaded from a legitimate source. The vulnerability could be used to brick (permanently disable) the BMC or the entire system, creating an impact even more severe than the BlackEnergy Kill Disk component. Supermicro has addressed the flaw by implementing signature verification to the firmware update tool.”]

Source: https://securityaffairs.co/wordpress/75999/hacking/flaw-supermicro-servers.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

SEA has stolen invoices that shows Microsoft charges FBI for user data

News

Greek police arrested a man running the BTC-e Bitcoin exchange to launder more than US$4bn worth of the Bitcoin