VDB

GCVE-110-BRLY-2024-023

GCVE-110-BRLY-2024-023
Advisory Published
Vulnetix · Advisory published September 18, 2024
BRLY-2024-023 Critical The BINARLY team has discovered that multiple Supermicro servers use an insecure RSA signing key (`RD1 BMC Test Key - DO NOT TRUST`) to implement the BMC Root of Trust security feature. The use of test keys poses a critical severity risk by making it trivial for remote attackers with administrative privileges to the BMC system to perform a malicious BMC firmware update and defeat U-Boot verified boot on affected devices. This results in a persistent compromise of both the BMC system and the main server operating system.

Browse GCVE Records

67,521 records in the GCVE database · Updated August 12, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›