Firmware Flaws Affect Supply Chain for Server Manufacturers
A supply chain security issue affects seven server manufacturers. The two vulnerabilities in baseboard management controller (BMC) firmware could be exploited to execute arbitrary code. They persist even after an operating system reinstallation, and can brick affected servers. The firmware, which is from a company called Vertiv, is used in Gigabyte motherboards.
https://www.sans.org/newsletters/newsbites/xxi/56
https://www.cyberscoop.com/lenovo-firmware-flaw-eclypsium-research
https://threatpost.com/firmware-bugs-plague-supply-chain/146519