CVE-2025-6198: Supermicro BMC firmware update validation bypass
Published Sep 19, 2025
·Updated
There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X13SEM-F . An attacker can update the system firmware with a specially crafted image.
Affected Software
2 affected components
Supermicro BMC firmware
Supermicro MBD-X13SEM-F
Event History
Sep 19, 2025
CVE Published
via MITRE·01:45 AM
Data Sourced
via MITRE·01:45 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeakness
Sep 24, 2025
News Published
via BleepingComputer·08:13 PM
News Published
via BleepingComputer·08:15 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-6198?
CVE-2025-6198 has been classified as a critical vulnerability due to its potential impact on firmware integrity.
2
How do I fix CVE-2025-6198?
To fix CVE-2025-6198, update the Supermicro BMC firmware to the latest version provided by Supermicro.
3
Who is affected by CVE-2025-6198?
CVE-2025-6198 affects users and administrators of Supermicro BMC firmware and the Supermicro MBD-X13SEM-F motherboard.
4
What type of attack is possible with CVE-2025-6198?
An attacker can exploit CVE-2025-6198 to update the system firmware with a specially crafted image.
5
Which Supermicro products are impacted by CVE-2025-6198?
CVE-2025-6198 impacts the Supermicro BMC firmware and the Supermicro MBD-X13SEM-F motherboard.