Database/Firmware, BMC & network fabric
Supermicro X10/X11 BMC (virtual media service): The BMC's virtual media service reuses socket file descriptors, so
Impact
The BMC's virtual media service reuses socket file descriptors, so an unauthenticated attacker inherits an existing client's privileges and can attach a virtual USB device to the server. In practice that means booting your node from the attacker's image, or dropping files onto a running host, without ever having a BMC credential. On a bare-metal GPU fleet this is a direct tenant-to-tenant and outsider-to-host compromise, and the implanted image outlives any OS reinstall.
Who can reach it
Anything with a network route to the BMC's virtual media port. No credentials, no user interaction. Supermicro boards are the whitebox default under a large share of neocloud GPU capacity, and BMCs on these boards are frequently found directly on a routable network.
What to do
BMC firmware flash per node, out-of-band, with the usual Supermicro caveat that the fixed version differs per board SKU - you need a per-model inventory before you can plan the rollout. Immediate config-only mitigation that actually works: block the virtual media ports (623, 5900, 623/udp and the 623x range Supermicro uses) at the network edge and put every BMC behind a jump host on a dedicated management VLAN. Do the network control first; the flash campaign will take weeks.
References
Related entries
- Lanner IAC-AST2500A BMC standard firmware 1.10.0: Arbitrary code execution as root on the BMC, at the maximum severityCVE-2021-26728 · Lanner IAC-AST2500A BMC standard firmware 1.10.0Critical
- Lanner IAC-AST2500A BMC firmware 1.10.0: Root on the BMC without any credential at all, because the vulnerable handlerCVE-2021-26729 · Lanner IAC-AST2500A BMC firmware 1.10.0Critical
- OpenBMC phosphor-net-ipmid (IPMI 2.0 RMCP+ / IPMI over LAN): The headline OpenBMC bugCVE-2021-39296 · OpenBMC phosphor-net-ipmid (IPMI 2.0 RMCP+ / IPMI over LAN)Critical
- Microchip maxView Storage Manager Redfish server (Adaptec SmartRAID / SmartHBA controllers), 3.00.23484 throughCVE-2024-22216 · Microchip maxView Storage Manager Redfish server (Adaptec SmartRAID / SmartHBA controllers), 3.00.23484 through…Critical
- Linux bnxt_en driver (XDP_REDIRECT double DMA unmap): A double DMA unmap in the XDP_REDIRECT pathCVE-2024-44984 · Linux bnxt_en driver (XDP_REDIRECT double DMA unmap)Critical
- Lantronix PremierWave 2050 console server (Web Manager): An attacker who can log into the web management console getsCVE-2021-21872 · Lantronix PremierWave 2050 console server (Web Manager)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.