Database/Firmware, BMC & network fabric
Supermicro X10/X11 BMC (virtual media service): The BMC's virtual media service reuses socket file descriptors, so
Impact
The BMC's virtual media service reuses socket file descriptors, so an unauthenticated attacker inherits an existing client's privileges and can attach a virtual USB device to the server. In practice that means booting your node from the attacker's image, or dropping files onto a running host, without ever having a BMC credential. On a bare-metal GPU fleet this is a direct tenant-to-tenant and outsider-to-host compromise, and the implanted image outlives any OS reinstall.
Who can reach it
Anything with a network route to the BMC's virtual media port. No credentials, no user interaction. Supermicro boards are the whitebox default under a large share of neocloud GPU capacity, and BMCs on these boards are frequently found directly on a routable network.
What to do
BMC firmware flash per node, out-of-band, with the usual Supermicro caveat that the fixed version differs per board SKU - you need a per-model inventory before you can plan the rollout. Immediate config-only mitigation that actually works: block the virtual media ports (623, 5900, 623/udp and the 623x range Supermicro uses) at the network edge and put every BMC behind a jump host on a dedicated management VLAN. Do the network control first; the flash campaign will take weeks.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.