Security researchers have uncovered vulnerabilities affecting the firmware of Supermicro server products. Discovered by the Eclypsium team, these vulnerabilities affect both older and newer models of Supermicro products, but the vendor is working on addressing the issues. These vulnerabilities do not put the safety of Supermicro products at direct risk, as they can only be exploited via malicious software/code (aka malware) already running on a system. Nevertheless, exploiting these vulnerabilities allows the malware to obtain an almost permanent foothold on infected systems by gaining the ability to survive server OS reinstalls by hiding in the hardware's firmware. The first of the flaws uncovered by Eclypsium researchers is not an actual vulnerability in the firmware's code, but in the configuration of some Supermicro products. Researchers say that some of these products come with firmware that uses an improper setting for the "Descriptor Region." The Descriptor Region is a security feature of Intel-based chipsets. This setting tells the chipset what areas of its own flash storage external parties can access to store data such as firmware or configuration files. According to Eclypsium researchers, some Supermicro products had an incorrectly set Descriptor Region that allowed software running on the OS (such as malware) to modify the Descriptor Region and then tamper with local firmware. "Eclypsium researchers have observed vulnerable descriptor access controls through runt...
Firmware Vulnerabilities Disclosed in Supermicro Server Products
BleepingComputer
·Published Jun 7, 2018
·Updated
Affected Software
3 affected components
Supermicro server firmware>=2008<=current
Supermicro X9DRi-LN4F+
Supermicro X10slm-f
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses newly discovered firmware vulnerabilities in Supermicro server products.
2
What security implications are discussed?
The vulnerabilities could potentially be exploited by attackers, compromising the security of affected Supermicro servers.
3
What products or software are affected?
The affected products include various Supermicro server firmware versions, specifically the Supermicro X9DRi-LN4F+ and Supermicro X10slm-f models.
4
Who discovered the vulnerabilities?
The vulnerabilities were uncovered by the security research team at Eclypsium.
5
Is Supermicro addressing these vulnerabilities?
Yes, Supermicro is actively working on addressing the identified firmware vulnerabilities.