Database/Firmware, BMC & network fabric

Opengear console server: Authentication bypass in the console server allowing remote attackers to modify settings
CVSS 7.5CVE-2011-3997Firmware, BMC & network fabriccurated
Impact
Authentication bypass in the console server allowing remote attackers to modify settings and reach every attached device's serial console — switches, BMCs, storage controllers
Who can reach it
Network / OOB LAN, unauthenticated
What to do
Console-server firmware upgrade; older units are EOL and the practical fix is replacing the appliance, which means a scheduled loss of out-of-band access to the rack
References
Related entries
- Supermicro IPMI BMC firmware - hardcoded WSMAN credentials (X9 before SMT_X9_315, X8 before SMT X8 312): The BMCCVE-2013-3620 · Supermicro IPMI BMC firmware - hardcoded WSMAN credentials (X9 before SMT_X9_315, X8 before SMT X8 312)High
- IBM Integrated Management Module (IMM/IMM2) IPMI 2.0 RAKP implementation: The vendor-acknowledged instance of the IPMICVE-2013-4037 · IBM Integrated Management Module (IMM/IMM2) IPMI 2.0 RAKP implementationHigh
- IPMI 2.0 RAKP (all vendors): Protocol design flawCVE-2013-4786 · IPMI 2.0 RAKP (all vendors)High
- AMD processors - page table walk traces in the last-level cache: The MMU's page table walks during address translationCVE-2017-5926 · AMD processors - page table walk traces in the last-level cacheHigh
- Cisco NX-OS (management interface ACL): The ACL you put on the management interface is not enforced, so traffic youCVE-2018-0090 · Cisco NX-OS (management interface ACL)High
- Dell iDRAC7 / iDRAC8 (web server URI parser): Directory traversal in the BMC's own HTTP front end lets an attackerCVE-2018-1211 · Dell iDRAC7 / iDRAC8 (web server URI parser)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.