Database/Firmware, BMC & network fabric
Supermicro IPMI BMC firmware - hardcoded WSMAN credentials (X9 before SMT_X9_315, X8 before SMT X8 312): The BMC
Impact
The BMC firmware ships with a static WSMAN credential pair that is identical on every board of that generation and cannot be changed by the operator. Recover it once - from a firmware image anyone can download - and you hold a working management login on every affected BMC in the world, including every one in your competitors' racks and every one in yours. Rotating your BMC passwords does nothing: one of the credential sets is a digest-auth account with an immutable password, and the other is a basic-auth account that simply fails to follow the admin password when you change it. For an operator this breaks the assumption underneath all BMC access control, which is that credentials are something you own.
Who can reach it
Network, pre-auth in effect - the credential is public knowledge, so possession of it is not a privilege the attacker had to earn. Any reachability to the BMC management interface is sufficient.
What to do
Firmware flash to SMT_X9_315 / SMT X8 312 or later; there is no configuration change that removes a hardcoded credential. Until then treat every affected BMC as having a permanent open account and rely entirely on network isolation - management VLAN, no tenant routability, jump-host-only access - because per-device credential hygiene provides zero protection here. This is also the item to check first when acquiring second-hand or colocated hardware, since the previous operator's firmware level is now your exposure.
References
Related entries
- IBM Integrated Management Module (IMM/IMM2) IPMI 2.0 RAKP implementation: The vendor-acknowledged instance of the IPMICVE-2013-4037 · IBM Integrated Management Module (IMM/IMM2) IPMI 2.0 RAKP implementationHigh
- IPMI 2.0 RAKP (all vendors): Protocol design flawCVE-2013-4786 · IPMI 2.0 RAKP (all vendors)High
- AMD processors - page table walk traces in the last-level cache: The MMU's page table walks during address translationCVE-2017-5926 · AMD processors - page table walk traces in the last-level cacheHigh
- Cisco NX-OS (management interface ACL): The ACL you put on the management interface is not enforced, so traffic youCVE-2018-0090 · Cisco NX-OS (management interface ACL)High
- Dell iDRAC7 / iDRAC8 (web server URI parser): Directory traversal in the BMC's own HTTP front end lets an attackerCVE-2018-1211 · Dell iDRAC7 / iDRAC8 (web server URI parser)High
- Arista EOS (BGP UPDATE): Malformed path attribute in a BGP UPDATE from a peer causes denial of serviceCVE-2018-5254 · Arista EOS (BGP UPDATE)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.