GPU VulnDB

Database/Firmware, BMC & network fabric

Intel Baseboard Management Controller firmware before 1.43.91f76955 (Intel server boards and systems): An unprivileged

CVE-2018-12171Firmware, BMC & network fabricINTEL-SA-00149curated

Impact

An unprivileged user can execute arbitrary code or force denial of service on the BMC. Owning the BMC is owning the node: virtual media boot, host power control, KVM, SOL, firmware update paths for BIOS and ME, and the SMBus. It is below-the-OS persistence in the strongest sense - the BMC has its own flash and its own OS, so nothing you do to the host image removes an implant there, and the node carries it into the next tenant. It also gives an attacker a fleet-wide physical-consequence lever: mass power-off of every node they can reach on the management network.

Who can reach it

Network access to the BMC without valid credentials. Anyone who can route to the out-of-band management network - which in practice includes anything that reaches an internet-exposed or flat-VLAN BMC, and any tenant if the OOB network is not fully separated.

What to do

BMC firmware update to 1.43.91f76955 or later, from Intel or the board ODM (Quanta, Wiwynn, Supermicro on Intel reference designs). BMC updates do not need a host reboot, so this is one you can roll without draining jobs - do it fleet-wide. In parallel: never expose BMCs to the internet, put them behind a jump host on a dedicated VRF, rotate to unique per-node credentials, and disable the host-side KCS interface.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.