Get a Pentest and security assessment of your IT network.

News

Flaw in update process for BMCs in Supermicro servers allows to deliver persistent malware or brick the server

A team of security researchers discovered a vulnerability in the baseboard management controller (BMC) hardware used by Supermicro servers. The update mechanism doesnt implement a code signing verification mechanism to check if the firmware is downloaded from a legitimate source. The vulnerability could be used to brick (permanently disable) the BMC or the entire system, creating an impact even more severe than the BlackEnergy Kill Disk component. Supermicro has addressed the flaw by implementing signature verification to the firmware update tool.”]

Source: https://securityaffairs.co/wordpress/75999/hacking/flaw-supermicro-servers.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Botnet authors use Evernote account as C&C Server

News

Canadian agency breached as hackers exploit CVE-2017-5638 flaw in Apache Struts 2