GPU VulnDB

Database/Firmware, BMC & network fabric

Supermicro X10/X11 BMC (virtual media service): The BMC's virtual media service reuses socket file descriptors, so

CVE-2019-16650Firmware, BMC & network fabricUSBAnywherecurated

Impact

The BMC's virtual media service reuses socket file descriptors, so an unauthenticated attacker inherits an existing client's privileges and can attach a virtual USB device to the server. In practice that means booting your node from the attacker's image, or dropping files onto a running host, without ever having a BMC credential. On a bare-metal GPU fleet this is a direct tenant-to-tenant and outsider-to-host compromise, and the implanted image outlives any OS reinstall.

Who can reach it

Anything with a network route to the BMC's virtual media port. No credentials, no user interaction. Supermicro boards are the whitebox default under a large share of neocloud GPU capacity, and BMCs on these boards are frequently found directly on a routable network.

What to do

BMC firmware flash per node, out-of-band, with the usual Supermicro caveat that the fixed version differs per board SKU - you need a per-model inventory before you can plan the rollout. Immediate config-only mitigation that actually works: block the virtual media ports (623, 5900, 623/udp and the 623x range Supermicro uses) at the network edge and put every BMC behind a jump host on a dedicated management VLAN. Do the network control first; the flash campaign will take weeks.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.