Back to Database
Status published
High
CVE-2024-10237
SMC BMC Firmware Image Authentication Design Issue
Vulnerability Description
There is a vulnerability in the BMC firmware image authentication design at Supermicro MBD-X12DPG-OA6 . An attacker can modify the firmware to bypass BMC inspection and bypass the signature verification process
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-10237
Credits & Attribution
No credits recorded in the NVD database.
More from SMCI
View All →CVE-2025-8727
A stack buffer overflow vulnerability exists in the Supermicro BMC Web function(SSL).
High
7.2
CVE-2025-8404
Stack buffer overflow vulnerability exists in the Supermicro BMC Shared library
Medium
5.5
CVE-2025-8076
A stack buffer overflow vulnerability exists in the Supermicro BMC Web function
High
7.2
CVE-2025-7937
Supermicro BMC firmware update validation bypass
High
7.2
CVE-2025-7704
Supermicro BMC SMASH services has a Stack-based buffer overflow vulnerability
Medium
5.4
Affected Vendor
SMCI
View all reports →Affected Software
MBD-X12DPG-OA6
Vulnerable Versions:
1.04.16
Timeline
Official Publish:
February 4th, 2025
Last Modified:
February 4th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
MITRE ATT&CK TTPs
T1553
Subvert Trust Controls
Defense Evasion
T1190
Exploit Public-Facing Application
Initial Access
T1078
Valid Accounts
Persistence
T1550
Use Alternate Authentication Material
Defense Evasion
T1565
Data Manipulation
Impact
T1557
Adversary-in-the-Middle
Credential Access
T1071
Application Layer Protocol
Command and Control
T1552
Unsecured Credentials
Credential Access
T1041
Exfiltration Over C2 Channel
Exfiltration