Database/Firmware, BMC & network fabric
Supermicro BMC virtual media (H11/H12/M11/X9/X10/X11): Virtual media service uses weak/absent encryption
CVSS 10.0CVE-2019-16649Firmware, BMC & network fabriccurated
Impact
Virtual media service uses weak/absent encryption and authentication — credential capture and attaching an arbitrary virtual USB device to the host, i.e. arbitrary boot media
Who can reach it
Network, unauthenticated
What to do
BMC firmware update across every affected generation; interim control is blocking the virtual-media ports (623/5900/5901) at the management-network boundary
References
Related entries
- Supermicro X10/X11 BMC (virtual media service): The BMC's virtual media service reuses socket file descriptors, soCVE-2019-16650 · Supermicro X10/X11 BMC (virtual media service)Critical
- Lanner IAC-AST2500A BMC standard firmware 1.10.0: Arbitrary code execution as root on the BMC, at the maximum severityCVE-2021-26728 · Lanner IAC-AST2500A BMC standard firmware 1.10.0Critical
- Lanner IAC-AST2500A BMC firmware 1.10.0: Root on the BMC without any credential at all, because the vulnerable handlerCVE-2021-26729 · Lanner IAC-AST2500A BMC firmware 1.10.0Critical
- OpenBMC phosphor-net-ipmid (IPMI 2.0 RMCP+ / IPMI over LAN): The headline OpenBMC bugCVE-2021-39296 · OpenBMC phosphor-net-ipmid (IPMI 2.0 RMCP+ / IPMI over LAN)Critical
- Microchip maxView Storage Manager Redfish server (Adaptec SmartRAID / SmartHBA controllers), 3.00.23484 throughCVE-2024-22216 · Microchip maxView Storage Manager Redfish server (Adaptec SmartRAID / SmartHBA controllers), 3.00.23484 through…Critical
- Linux bnxt_en driver (XDP_REDIRECT double DMA unmap): A double DMA unmap in the XDP_REDIRECT pathCVE-2024-44984 · Linux bnxt_en driver (XDP_REDIRECT double DMA unmap)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.