WelcomeUser Guide
ToSPrivacyCanary
DonateBugsLicense

©2025 Poal.co

551

Something to consider if buying used hardware.

Archive: https://archive.today/EFbFF

From the post:

>Servers running on motherboards sold by Supermicro contain high-severity vulnerabilities that can allow hackers to remotely install malicious firmware that runs even before the operating system, making infections impossible to detect or remove without unusual protections in place. One of the two vulnerabilities is the result of an incomplete patch Supermicro released in January, said Alex Matrosov, founder and CEO of Binarly, the security firm that discovered it. He said that the insufficient fix was meant to patch CVE-2024-10237, a high-severity vulnerability that enabled attackers to reflash firmware that runs while a machine is booting. Binarly discovered a second critical vulnerability that allows the same sort of attack.

Something to consider if buying used hardware. Archive: https://archive.today/EFbFF From the post: >>Servers running on motherboards sold by Supermicro contain high-severity vulnerabilities that can allow hackers to remotely install malicious firmware that runs even before the operating system, making infections impossible to detect or remove without unusual protections in place. One of the two vulnerabilities is the result of an incomplete patch Supermicro released in January, said Alex Matrosov, founder and CEO of Binarly, the security firm that discovered it. He said that the insufficient fix was meant to patch CVE-2024-10237, a high-severity vulnerability that enabled attackers to reflash firmware that runs while a machine is booting. Binarly discovered a second critical vulnerability that allows the same sort of attack.

(post is archived)

[–] 3 pts

Yep. Cisco famously setup extremely complex shipping protocols for some clients (that paid more for it) specifically to avoid USA's Tailored access operations (TAO) intercepting the hardware in transit and either modifying the hardware entirely or replacing the firmware with a intentionally hijacked firmware.