Database/Firmware, BMC & network fabric

Raritan PX rack PDU (before firmware 1.5.11, DPXR20A-16 and related PX models): The PDU's IPMI interface accepts
Impact
The PDU's IPMI interface accepts 'cipher suite 0' (aka cipher zero), a known-broken IPMI auth mode that accepts any password. An attacker who reaches the IPMI port can issue arbitrary IPMI commands with no valid credential — including power-control commands to cut or cycle outlets feeding whatever racks that PDU serves, tenant-owned or not.
Who can reach it
Fully remote and unauthenticated over the network-reachable IPMI port — the attacker just needs to request cipher suite 0 and supply any password; the PDU accepts it.
What to do
Firmware upgrade to 1.5.11 or later, which disables cipher-zero support. If a firmware upgrade isn't immediately possible, a network-segmentation change to firewall off the IPMI port from anything but a trusted management VLAN is the compensating control — this is the same 'IPMI cipher zero' class of bug that hit many BMC vendors around the same era, so audit for other devices on the same segment too. Flash each PDU one at a time; outlets keep powering their load during the update, but remote power-control briefly drops.
References
Related entries
- Supermicro BMC virtual media (H11/H12/M11/X9/X10/X11): Virtual media service uses weak/absent encryptionCVE-2019-16649 · Supermicro BMC virtual media (H11/H12/M11/X9/X10/X11)Critical
- Supermicro X10/X11 BMC (virtual media service): The BMC's virtual media service reuses socket file descriptors, soCVE-2019-16650 · Supermicro X10/X11 BMC (virtual media service)Critical
- Lanner IAC-AST2500A BMC standard firmware 1.10.0: Arbitrary code execution as root on the BMC, at the maximum severityCVE-2021-26728 · Lanner IAC-AST2500A BMC standard firmware 1.10.0Critical
- Lanner IAC-AST2500A BMC firmware 1.10.0: Root on the BMC without any credential at all, because the vulnerable handlerCVE-2021-26729 · Lanner IAC-AST2500A BMC firmware 1.10.0Critical
- OpenBMC phosphor-net-ipmid (IPMI 2.0 RMCP+ / IPMI over LAN): The headline OpenBMC bugCVE-2021-39296 · OpenBMC phosphor-net-ipmid (IPMI 2.0 RMCP+ / IPMI over LAN)Critical
- Microchip maxView Storage Manager Redfish server (Adaptec SmartRAID / SmartHBA controllers), 3.00.23484 throughCVE-2024-22216 · Microchip maxView Storage Manager Redfish server (Adaptec SmartRAID / SmartHBA controllers), 3.00.23484 through…Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.