Database/Firmware, BMC & network fabric
Intel Baseboard Management Controller firmware (Intel server boards and systems) - web/network services: Heap
Impact
Heap corruption in the BMC's network-facing code, unauthenticated, yielding information disclosure, privilege escalation and denial of service; the same advisory bundles an outright authentication bypass and a session-validation failure. A compromised BMC is permanent control of the node underneath the OS - virtual media, power, KVM, and the write path to BIOS and ME firmware. It survives tenant reimage by construction, and a fleet-wide compromise of BMCs is a fleet-wide power-off button, which is a hall-level physical event, not a per-node one.
Who can reach it
Unauthenticated network access to the BMC's services. Any host on the OOB management network, anything that reaches a BMC exposed through a misconfigured route or a flat provisioning VLAN, and - where the KCS host interface is enabled - a tenant with root on the node.
What to do
BMC firmware update from Intel / the board ODM (Quanta, Wiwynn, Supermicro on Intel designs). No host reboot needed, so it can be rolled without draining training jobs, but it must be staged per board family and verified per node. Structurally: dedicated OOB network with no tenant path, jump-host-only access, unique credentials per node, disable KCS on bare-metal SKUs, and re-flash the BMC as part of node reclaim between tenants rather than trusting its current image.
References
Related entries
- Rittal SK 3232-series chiller web interface (built on Carel pCOWeb firmware A1.5.3-B1.2.4): Whoever can reachCVE-2019-13553 · Rittal SK 3232-series chiller web interface (built on Carel pCOWeb firmware A1.5.3-B1.2.4)Critical
- Dell iDRAC7/8: Stack buffer overflow in the iDRAC web server — unauthenticated RCE on the BMCCVE-2019-3705 · Dell iDRAC7/8Critical
- Dell iDRAC9: Authentication bypass in the iDRAC9 web interface — full out-of-band control of the serverCVE-2019-3706 · Dell iDRAC9Critical
- Dell iDRAC9: Authentication bypass via the WS-MAN interfaceCVE-2019-3707 · Dell iDRAC9Critical
- ASPEED AST2400 / AST2500 BMC SoC: Arbitrary read/write of the BMC's entire physical address space **from the host CPU**CVE-2019-6260 · ASPEED AST2400 / AST2500 BMC SoCCritical
- NVIDIA DGX BMC (AMI firmware): Hard-coded credentials in the DGX BMC firmwareCVE-2020-11483 · NVIDIA DGX BMC (AMI firmware)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.