Database/Firmware, BMC & network fabric
Intel Baseboard Management Controller firmware (Intel server boards and systems) - web/network services: Heap
Impact
Heap corruption in the BMC's network-facing code, unauthenticated, yielding information disclosure, privilege escalation and denial of service; the same advisory bundles an outright authentication bypass and a session-validation failure. A compromised BMC is permanent control of the node underneath the OS - virtual media, power, KVM, and the write path to BIOS and ME firmware. It survives tenant reimage by construction, and a fleet-wide compromise of BMCs is a fleet-wide power-off button, which is a hall-level physical event, not a per-node one.
Who can reach it
Unauthenticated network access to the BMC's services. Any host on the OOB management network, anything that reaches a BMC exposed through a misconfigured route or a flat provisioning VLAN, and - where the KCS host interface is enabled - a tenant with root on the node.
What to do
BMC firmware update from Intel / the board ODM (Quanta, Wiwynn, Supermicro on Intel designs). No host reboot needed, so it can be rolled without draining training jobs, but it must be staged per board family and verified per node. Structurally: dedicated OOB network with no tenant path, jump-host-only access, unique credentials per node, disable KCS on bare-metal SKUs, and re-flash the BMC as part of node reclaim between tenants rather than trusting its current image.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.