CVE-2024-10237 describes a critical vulnerability in the BMC firmware image authentication design of Supermicro MBD-X12DPG-OA6. An authenticated attacker can bypass signature verification to modify the firmware, potentially leading to a complete compromise of the Baseboard Management Controller. Rated 7.2 HIGH, this vulnerability allows for remote, low-complexity attacks resulting in high impact to confidentiality, integrity, and availability. While no public exploit code exists, the vulnerability has garnered significant community discussion and media coverage, indicating heightened awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| SMCI | MBD-X12DPG-OA6 | 1.04.16CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.