Database/Firmware, BMC & network fabric
IPMI 2.0 RAKP (all vendors): Protocol design flaw
Impact
Protocol design flaw — RAKP message 2 returns an HMAC over the password hash to any unauthenticated requester, enabling offline cracking of every BMC account on the fleet
Who can reach it
Network / IPMI over LAN, unauthenticated
What to do
Cannot be patched — it is the IPMI 2.0 spec. Only real remediation is disabling IPMI-over-LAN entirely and moving to Redfish with strong per-node unique credentials, which breaks legacy provisioning tooling
Fleet impact
How widespread
universal - IPMI-over-LAN is enabled on essentially every server BMC unless deliberately disabled
Cost to remediate
unpatchable-mitigate-only - **this is a flaw in the IPMI 2.0 specification itself**, so no firmware fixes it; the only remediation is disabling IPMI-over-LAN fleet-wide or hard-isolating UDP/623, which breaks tooling that depends on it
Why it hits the whole fleet
A vulnerable BMC hands out a password-derived HMAC-SHA1 before authentication, so any host that can reach the management network harvests offline-crackable BMC credentials for every node at once - and BMC passwords are typically identical across a fleet built from one golden config.
References
Related entries
- AMD processors - page table walk traces in the last-level cache: The MMU's page table walks during address translationCVE-2017-5926 · AMD processors - page table walk traces in the last-level cacheHigh
- Cisco NX-OS (management interface ACL): The ACL you put on the management interface is not enforced, so traffic youCVE-2018-0090 · Cisco NX-OS (management interface ACL)High
- Dell iDRAC7 / iDRAC8 (web server URI parser): Directory traversal in the BMC's own HTTP front end lets an attackerCVE-2018-1211 · Dell iDRAC7 / iDRAC8 (web server URI parser)High
- Arista EOS (BGP UPDATE): Malformed path attribute in a BGP UPDATE from a peer causes denial of serviceCVE-2018-5254 · Arista EOS (BGP UPDATE)High
- Arista EOS (VxLAN agent): Malformed ARP packets crash the VxLAN software forwarding agentCVE-2019-18948 · Arista EOS (VxLAN agent)High
- Lenovo XClarity Administrator (LXCA) - unauthenticated config file access: Unauthenticated access to LXCA configurationCVE-2019-6193 · Lenovo XClarity Administrator (LXCA) - unauthenticated config file accessHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.