Database/Firmware, BMC & network fabric

HPE iLO 5 (firmware update security restriction bypass): Bypass of the security restrictions that guard iLO 5 firmware
Impact
Bypass of the security restrictions that guard iLO 5 firmware updates. The severity number undersells what this is: the firmware-update gate is the control that stops an attacker from writing their own image to the service processor. Defeat it and the attacker installs persistent BMC firmware of their choosing - the deepest and most durable implant available on the node, below the hypervisor and untouched by any host reimage. On a bare-metal cloud, a node whose iLO firmware was replaced by a previous tenant never comes clean again through normal reprovisioning.
Who can reach it
Local exploitation - an attacker who already has a foothold on the node or its iLO context, not an unauthenticated remote attacker. The realistic path in a bare-metal fleet is a tenant with host-level access using it during their tenancy to leave something behind for the next one.
What to do
Flash iLO 5 to v1.37 or later - out-of-band, per-node, no host reboot and no job drain. Complementary control that matters more than the version number: enable and actually check the iLO firmware integrity/attestation features HPE exposes, and verify iLO firmware version and measurement as part of node reprovisioning between tenants rather than trusting that a wipe covered it.
References
Related entries
- AMI MegaRAC SPx (BMC hard-coded credentials): Hard-coded credentials inside the BMC firmwareCVE-2023-34473 · AMI MegaRAC SPx (BMC hard-coded credentials)Medium
- Cisco FXOS / NX-OS (LLDP frame handling denial of service): An unauthenticated adjacent attacker sends crafted LLDPCVE-2024-20294 · Cisco FXOS / NX-OS (LLDP frame handling denial of service)Medium
- AMD Zynq UltraScale+ - CSU runtime service address validation in PMU firmware: The PMU firmware on Zynq UltraScale+CVE-2025-0038 · AMD Zynq UltraScale+ - CSU runtime service address validation in PMU firmwareMedium
- TCG TPM 2.0 reference implementation (CryptHmacSign): Out-of-bounds read in the reference implementation's HMAC signingCVE-2025-2884 · TCG TPM 2.0 reference implementation (CryptHmacSign)Medium
- Linux kernel (drivers/infiniband/hw/irdma): A stale flag caused the CQ memory-registration path to read one elementCVE-2026-74346 · Linux kernel (drivers/infiniband/hw/irdma)Medium
- Linux kernel InfiniBand connection manager drivers/infiniband/core/cma.c and cm.c - cm_work_handler race: A race in theCVE-2011-0695 · Linux kernel InfiniBand connection manager drivers/infiniband/core/cma.c and cm.c - cm_work_handler raceMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.