Database/Firmware, BMC & network fabric
Intel AMT (HTTP handler) in Intel CSME firmware: A buffer overflow in AMT's HTTP handler allows arbitrary code
Impact
A buffer overflow in AMT's HTTP handler allows arbitrary code execution with AMT privileges. AMT's HTTP handler is what serves the out-of-band management interface, so exploitation gives the attacker the same below-the-OS control AMT itself has.
Who can reach it
Reachable through the AMT network interface on provisioned machines.
What to do
Fixed in Intel CSME/SPS firmware, which reaches you as an OEM BIOS or firmware package - not as a microcode or OS update. That means: wait for your server vendor to ship it, drain the node, flash, and reboot. OEM availability is the long pole and routinely lags the Intel advisory by one or more quarters on server platforms. Track it per platform SKU, because vendors ship these unevenly across their own product lines. Immediate compensating control is to unprovision AMT where you do not use it and firewall the AMT ports where you do.
References
Related entries
- Brocade Fabric OS Webtools (firmware update section): A remote authenticated attacker can abuse the WebtoolsCVE-2018-6442 · Brocade Fabric OS Webtools (firmware update section)High
- Eaton UPS 9PX 8000 SP administration panel: CSRF on the change-password function plus reflected XSS: an attacker forcesCVE-2018-9281 · Eaton UPS 9PX 8000 SP administration panelHigh
- Intel Ethernet 700 Series Controller firmware (X710/XL710/XXV710): Buffer overflow in the adapter firmware of Intel'sCVE-2019-0140 · Intel Ethernet 700 Series Controller firmware (X710/XL710/XXV710)High
- Intel CSME / TXE: A heap overflow in a CSME subsystem reachable by an unauthenticated attacker for privilege escalationCVE-2019-0169 · Intel CSME / TXEHigh
- Supermicro BMC virtual media subsystem on X8STi-F with IPMI firmware 2.06: The researcher's own descriptionCVE-2019-19642 · Supermicro BMC virtual media subsystem on X8STi-F with IPMI firmware 2.06High
- NVIDIA DGX BMC (AMI firmware): CSRF in the BMC web applicationCVE-2020-11485 · NVIDIA DGX BMC (AMI firmware)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.