Researchers find that weaknesses in Supermicro hardware would let an attacker leave a persistent and hidden backdoor on IBM's cloud “bare-metal” servers
IBM rated the severity “low”, while Eclypsium assigned a 9.3 “critical” CVE 3. Solid work by @ABazhaniuk and team. http://eclypsium.com/... Kenn White / @kennwhite : Researchers at @eclypsium demonstrate persistent implants on IBM SoftLayer via user-accessible unsecured motherboard management controller, survived server reprovisioning to new customers. http://twitter.com/...
Context & Ripple Effects
This disclosure lands mid-arc for Supermicro. A year earlier, Bloomberg reported that Supermicro's own firmware portal was breached in 2015, with Facebook among customers who downloaded malware from it. Now Eclypsium shifts the focus from distribution channels to the hardware itself: an unsecured baseboard management controller on Supermicro boards inside IBM's SoftLayer bare-metal cloud can host implants that persist through reprovisioning.
The finding matters because bare-metal clouds sell customers a freshly wiped machine between tenants — and this attack defeats exactly that guarantee. The severity dispute frames it: IBM rates the issue low while Eclypsium scores the CVE 9.3 critical, a gap that itself signals how differently providers and firmware-security researchers weigh BMC exposure.
First-order effects
- IBM SoftLayer bare-metal customers inherit a tenancy-isolation gap: an attacker who reaches the unsecured management controller can leave an implant that survives the wipe meant to protect the next tenant.
- IBM and Eclypsium are publicly split on severity — low versus a 9.3 critical score — leaving customers to decide for themselves whether to demand remediation or hardware changes.
Second-order effects
- Supermicro's BMC surface comes under sustained scrutiny: months later researchers find related motherboard flaws allowing remote virtual USB drives, with 47,000+ potentially exposed devices online (the follow-up disclosure), forcing patching at fleet scale across every vendor building on its boards.
- Bare-metal cloud rivals must now answer whether their own fleets have the same user-accessible management-controller exposure, since 'freshly provisioned' is only as trustworthy as the BMC wiping it.
Third-order effects
- If BMC-level persistence proves routine, trust in commodity server hardware shifts toward verifiable firmware provenance — a direction US investigators' claims of tampered Supermicro chips with backdoor code (reported two years later) push further still.
- Hyperscalers and cloud buyers gain leverage to demand attested, locked-down management controllers from board vendors, making firmware security a procurement requirement rather than a best effort.
The trend: Cloud infrastructure security is expanding from software images down to the motherboard management layer, where one vendor's BMC design decision propagates into every tenant-isolation promise built on top of it.