Nvidia OSR (@AlexTereshkin, @Adam_pi3) reveals high-impact Supermicro BMC vulnerabilities (CVE-2024-10237/38/39). Binarly REsearch documenting the details:
👻Ghost in the Controller: Abusing Supermicro BMC Firmware Verification.
Read the full story: https://t.co/uzMnkdXflY
Together with @AlexTereshkin we managed to summarize NVIDIA Offensive Security Research (OSR) work on breaking BMC (reference to our DefCon talk https://t.co/4VBhcLhcUa). This blog post also includes a link to the full paper.
I'm delighted to share that our talk "How to Secure Unique Ecosystem Shipping 1 Billion+ Cores?" has been accepted to @BlackHatEvents#BHUSA 2025!
How to create a secure unique ecosystem from scratch? What's Separation Kernel? How and why to modify RISC-V? come to our talk! :)
Found a nice little SecureBoot bypass in a sizable bunch of UEFI firmwares, will share the details when able.
Meanwhile, this is the SHA2-256 of the PoC tool to trigger it:
530584749f90d187ac20f77c6d4bb2e09ec1c852090962dfab01c4274a8a6d2d
🚨New! "CVE-2024-36435 Deep-Dive: The Year’s Most Critical BMC Security Flaw."
🔥Classic buffer overflow vulnerabilities resurface in BMCs, remotely opening the gates from the castle.
🏆Kudos to @AlexTereshkin for the initial discovery and disclosure!
https://t.co/lVQBjboiwf
I'm trying to start a positive security trend of #ResearchRespect wherein we give shoutouts to researchers whose work we really respect and describe why. I'll go first (in no particular order) with "Attacking Intel BIOS" by Rafal Wojtczuk and @AlexTereshkin at BlackHat 2009
#LogoFAIL abstract is online! Embargo ends on Dec 6th. LogoFAIL impacting all major IBVs reverence code: AMI, Insyde, and Phoenix. Also, this attack is not silicon-specific but UEFI-specific🔥 and impacts ARM and x86.
Kudos to @Binarly_io REsearch team!
https://t.co/igcLHRGvZ8
🔬OSR Team keeps rocking! @AlexTereshkin and @Adam_pi3 keep digging into BMC and FW rabbit hole.
🔥The main caveat is that most of those discoveries are related to IBVs reference code and impact the entire industry.
⛓️One vendor fix != Industry
⛓️Supply Chain Security is hard!
What is BMC? Should we care about BMC's security? How easy is it to hack it?
You can find all the answers during our talk (CC @AlexTereshkin) at @defcon at 3:30pm on Saturday ;-) Join us!
https://t.co/AHL2hOTMQg
CC: @mbazaliy, @igoooo, NVDA RISC-V FW dude
#DEFCON31#Defcon
"Accepted Presentation:
Breaking BMC: The Forgotten Key to the Kingdom
Congrats! Your @defcon 31 Submission is accepted!"
I'm super exited about the 3rd DefCon talk in a row! :)
CC: Alex Tereshkin (@AlexTereshkin)
#defcon31#defcon