Database/Firmware, BMC & network fabric

QLogic 4Gb Fibre Channel 5.5.2.6.0 and 4/8Gb SAN 7.10.1.20.0 switch modules for IBM BladeCenter: Three undocumented
Impact
Three undocumented accounts - support, diags and prom - each with a fixed password, baked into the FC switch module firmware. Anyone who knows them owns the switch module: zoning, port state, firmware. The reason this belongs in a modern GPU-datacenter database is not BladeCenter itself but the pattern - embedded FC switch modules and SAS/FC expander boards inherited with second-hand chassis carry vendor service accounts that no amount of operator password hygiene touches, and nothing in a normal build process ever looks for them.
Who can reach it
Anyone who can reach the module's management interface (telnet/SSH/web) on the chassis management network. Credentials are public.
What to do
Unfixable by configuration - the accounts are in firmware. Either upgrade to a firmware release where they are removed, if one exists for your module, or retire the module. Practically, for inherited or second-hand chassis: treat every embedded switch/expander module as carrying vendor backdoor accounts until proven otherwise, keep chassis management on an isolated segment no tenant or workload VLAN can route to, and make 'scan for vendor service accounts' part of hardware intake rather than something you do after an incident.
References
Related entries
- Schneider Electric MGE Network Management Card Transverse (MGE UPS / MGE STS): The card's integrated web serverCVE-2018-7243 · Schneider Electric MGE Network Management Card Transverse (MGE UPS / MGE STS)Critical
- Schneider Electric MGE Network Management Card Transverse (MGE UPS / MGE STS): On default settings without SSL enabledCVE-2018-7246 · Schneider Electric MGE Network Management Card Transverse (MGE UPS / MGE STS)Critical
- APC UPS Network Management Card 2 (AOS 6.5.6): When Remote Monitoring is turned on and then off again, the credentialsCVE-2018-7820 · APC UPS Network Management Card 2 (AOS 6.5.6)Critical
- Intel CSME 12.0.0-12.0.34: A buffer overflow in a CSME subsystem reachable over the network by an unauthenticatedCVE-2019-0153 · Intel CSME 12.0.0-12.0.34Critical
- Intel Baseboard Management Controller firmware (Intel server boards and systems) - web/network services: HeapCVE-2019-11171 · Intel Baseboard Management Controller firmware (Intel server boards and systems) - web/network servicesCritical
- Rittal SK 3232-series chiller web interface (built on Carel pCOWeb firmware A1.5.3-B1.2.4): Whoever can reachCVE-2019-13553 · Rittal SK 3232-series chiller web interface (built on Carel pCOWeb firmware A1.5.3-B1.2.4)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.