Skip to main content
Vulnerabilities in Supermicro BMC Firmware, September 2025

Vulnerability Disclosure:

The purpose of this disclosure is to communicate the potential vulnerabilities affecting Supermicro products that were reported by an external researcher.

Acknowledgement:

Supermicro would like to acknowledge the work done by the Binarly team for discovering potential vulnerabilities in Supermicro BMC Firmware.

Summary:

Two security issues have been discovered in select Supermicro boards. These issues may affect Supermicro BMC Firmware.

CVE IDSeverityIssue TypeDescription
MediumImproper Verification of Cryptographic Signature

A crafted firmware image can bypass the Supermicro BMC firmware verification logic of RoT 1.0 to update the system firmware. The crafted image has a customized PDBA table of RoT 1.0 to redirect the program to the fake PDBA table in the unsigned region.

Supermicro CVSSv3 score: 6.6 (AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H)

MediumImproper Verification of Cryptographic Signature

A crafted firmware image can bypass the Supermicro BMC firmware verification logic of Signing Table to update the system firmware. The crafted image has a customized signing table to redirect the program to the fake signing table in the unsigned region.

Supermicro CVSSv3 score: 6.4 (AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H)

Affected products:

Supermicro BMC in select motherboards.

CVE-2025-6198
CVE-2025-6198
MotherboardBMC FW with the Fix
MBD-B12DPT01.07.01
MBD-B12SPE-CPU-TF01.07.01
MBD-BH12SSI-M2501.07.01
MBD-B12DPT-601.07.01
MBD-H12SSFF-AN601.07.01
MBD-X12DPG-OA6-GD201.07.01
MBD-X12DPG-OA601.07.01
MBD-B12DPE-601.07.01
MBD-B12SPE-CPU-25G01.07.01
MBD-X12DGQ-R01.07.01
MBD-X12DPG-QR01.07.01
MBD-H12DSG-CPU6-TI03601.07.01
MBD-X12STW-F01.07.01
MBD-X12STW-TF01.07.01
MBD-B3ST1-CPU-00101.07.01
MBD-X13DEM01.05.01
MBD-X13DET-B01.05.01
MBD-X13DSF-A01.05.01
MBD-X13SEDW-F01.05.01
MBD-X13SEED-F01.05.01
MBD-X13SEED-SF01.05.01
MBD-X13SEFR-A01.05.01
MBD-X13SEM-F01.05.01
MBD-X13SEM-TF01.05.01
MBD-X13SET-PT01.05.01
MBD-X13SEVR-SP13F01.05.01
MBD-X13OEI-CPU01.05.01
MBD-B13DEE01.05.01
MBD-B13DET01.05.01
MBD-B13SEE-CPU-25G01.05.01
MBD-B13SEG01.05.01
MBD-B4SA1-CPU01.05.01
MBD-B4SC1-CPU01.05.01
MBD-H13QSH01.05.01
MBD-H13SRH01.05.01
MBD-H13SSF01.05.01
MBD-H13SSH01.05.01
MBD-G1SMH-G01.05.01
MBD-G1SMH01.05.01
MBD-G2DMH-G01.05.01
MBD-G2DMH-GI01.05.01
MBD-X13DEH01.05.01
MBD-X13SAW-F01.05.01
MBD-X13SAW-TLN4F01.05.01
MBD-X13SCW-F-B01.05.01
MBD-X13SCW-F-O01.05.01
MBD-X13SCW-F01.05.01
MBD-X14DBM-AP01.03.00.01
MBD-X14DBM-APL01.03.00.01
MBD-X14DBM-SP01.03.00.01
MBD-X14DBT-B01.03.00.01
MBD-X14DBT-FAP01.03.00.01
MBD-X14DBT-FLAP01.03.00.01
MBD-X14QBH+01.03.00.01
MBD-X14SBH-AP01.03.00.01
MBD-X14SBH01.03.00.01
MBD-X14SBM-TF01.03.00.01
MBD-X14SBM-TP4F01.03.00.01
MBD-X14SDV-20C-SP3F01.03.00.01
MBD-X14SDV-32C-SP3F01.03.00.01
MBD-X14SDV-36C-SP3F01.03.00.01
MBD-X14SDV-36CE-SP3F01.03.00.01
MBD-X14SDV-42C-SP3F01.03.00.01
MBD-X14SDW-36C-SP9F01.03.00.01
MBD-X14SDW-36CE-SP9F01.03.00.01
MBD-X14SDW-42C-SP9F01.03.00.01
MBD-H13DSG-OM01.05.01
MBD-B3SD1-20C-25G01.07.01
MBD-X14SBHM01.03.00.01
MBD-B14DBE-AP01.03.00.01
MBD-B14DBE01.03.00.01
MBD-B14DBT01.03.00.01
MBD-B14SBE-CPU-25G01.03.00.01
MBD-B14SBE-CPU-AP01.03.00.01
MBD-X14DBG-GD01.03.00.01
MBD-X14DBG-XAP01.03.00.01
MBD-X14SBT-G01.03.00.01
MBD-X14SBT-GAP01.03.00.01
MBD-H14DSH-TI03601.03.00.01
MBD-H14DST-F01.03.00.01
MBD-H14DSG-OD01.03.00.01
MBD-H14DSG-OM01.03.00.01
MBD-X14DBG-MAP01.03.00.01
MBD-X14SBGM01.03.00.01
MBD-X14DBG-LC+01.03.00.01
MBD-X14DBG-LC01.03.00.01
MBD-X11DPFF-SNR1.01.26
MBD-X11DPT-BR1.01.26
MBB-CMM-00301.02.04
MBM-CMM-6-01-FI00501.02.04
MBM-CMM-FIO01.02.04
MBB-CMM-601.02.04
MBM-CMM-6-01-HN00401.02.04
MBM-CMM-FIO-01-FI00501.02.04
MBM-CMM-601.02.04
MBM-CMM-6-IN00101.02.04
MBD-X12DPT-B01.07.01
CVE-2025-7937
CVE-2025-7937
MotherboardBMC FW with the Fix
MBD-X11DGQ3.77.16
MBD-X11DPD-L3.77.16
MBD-X11DPD-M253.77.16
MBD-X11DPFF-SN3.77.16
MBD-X11DPL-I3.77.16
MBD-X11DPS-R3.77.16
MBD-X11DPS-RE3.77.16
MBD-X11DPT-L3.77.16
MBD-X11DSC+3.77.16
MBD-X11DSF-E3.77.16
MBD-X11DSF3.77.16
MBD-X11SCW-F-AM0473.77.16
MBD-X11SCW-F3.77.16
MBD-X11SRI-IF3.77.16
MBD-B12DPT01.07.03
MBD-B12SPE-CPU-TF01.07.03
MBD-BH12SSI-M2501.07.03
MBD-B12DPT-601.07.03
MBD-H12SSFF-AN601.07.03
MBD-X12DPG-OA6-GD201.07.03
MBD-X12DPG-OA601.07.03
MBD-B12DPE-601.07.03
MBD-B12SPE-CPU-25G01.07.03
MBD-X12DGQ-R01.07.03
MBD-X12DPG-QR01.07.03
MBD-H12DSG-CPU6-TI03601.07.03
MBD-X12STW-F01.07.03
MBD-X12STW-TF01.07.03
MBD-B3ST1-CPU-00101.07.03
MBD-X11DPFF-SNR1.01.26
MBD-X11DPT-BR1.01.26
MBD-X12DPT-B01.07.03

Remediation:

Affected Supermicro motherboard SKUs will require a BMC update to mitigate these potential vulnerabilities.

An updated BMC firmware had been created to mitigate these potential vulnerabilities. Supermicro is currently testing and validating affected products. Please check Release notes for the resolution.

Exploitation and Public Announcements:

Supermicro is not aware of any malicious exploitation of these vulnerabilities in the wild.