CVE-2025-12006: Supermicro BMC firmware update validation bypass
There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X12STW-F . An attacker can update the system firmware with a specially crafted image.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12006?
CVE-2025-12006 has been classified as a critical severity vulnerability due to its potential for exploitation.
How do I fix CVE-2025-12006?
To fix CVE-2025-12006, users should apply the latest firmware update released by Supermicro that addresses the validation bypass issue.
What systems are affected by CVE-2025-12006?
CVE-2025-12006 specifically affects the Supermicro MBD-X12STW-F motherboards.
What are the potential impacts of exploiting CVE-2025-12006?
Exploitation of CVE-2025-12006 could allow an attacker to install unauthorized firmware, potentially leading to system compromise.
Is there any known exploit for CVE-2025-12006?
As of now, there are no public exploits available for CVE-2025-12006, but the vulnerability poses a significant risk if left unpatched.