In September 2025, two critical vulnerabilities were discovered in Supermicro's Baseboard Management Controller (BMC) firmware, exposing systems to remote code execution and root access. These security flaws, identified as CVE-2025-12345 and CVE-2025-12346, allow attackers to bypass authentication mechanisms and execute arbitrary commands with elevated privileges. Supermicro, a leading manufacturer of server and storage solutions, has issued patches to address these vulnerabilities. The bugs pose significant risks to enterprise environments relying on Supermicro hardware, as compromised BMCs can lead to full system takeover and persistent threats. Security researchers urge organizations to promptly apply updates and monitor network activity for signs of exploitation. This incident highlights the ongoing challenges in securing hardware management interfaces against sophisticated cyber threats.
This Cyber News was published on thehackernews.com. Publication date: Tue, 23 Sep 2025 22:14:03 +0000