Database/Firmware, BMC & network fabric
Supermicro BMC virtual media subsystem on X8STi-F with IPMI firmware 2.06: The researcher's own description
Impact
The researcher's own description is the operator-relevant one: a persistent backdoor on the BMC. Virtual media is the single most dangerous BMC feature to lose control of, because it is the mechanism by which an attacker attaches their own boot image to a node and reboots into it. Combined with command injection in the same subsystem, the attacker gets both code on the controller and the ability to boot the host into whatever they want - the complete out-of-band takeover, surviving any host-side remediation. Shell metacharacters in the ShareHost and ShareName fields of the /rpc/setvmdrive.asp handler reach a command interpreter on the controller.
Who can reach it
An authenticated attacker who can send HTTP requests to the BMC's IP address. Any valid BMC credential plus a route to the management network is sufficient.
What to do
This is legacy X8-generation hardware and firmware updates for it are effectively unavailable, so treat this as a case where flashing is not a real option. The controls that work are structural: disable virtual media on the BMC where the platform allows it, isolate these BMCs onto a management VLAN with no route from tenant or general corporate networks, and plan the hardware out. If X8-era Supermicro boards are still carrying production workloads, that is a fleet-lifecycle decision, not a patching decision.
References
Related entries
- NVIDIA DGX BMC (AMI firmware): CSRF in the BMC web applicationCVE-2020-11485 · NVIDIA DGX BMC (AMI firmware)High
- Rittal PDU-3C002DEC rack PDU firmware (through 5.15.40): Arbitrary code execution on the rack PDUCVE-2020-11953 · Rittal PDU-3C002DEC rack PDU firmware (through 5.15.40)High
- OpenBMC phosphor-host-ipmid (user_channel/passwd_mgr.cpp, /etc/ipmi-pass): The file holding IPMI account passwordsCVE-2020-14156 · OpenBMC phosphor-host-ipmid (user_channel/passwd_mgr.cpp, /etc/ipmi-pass)High
- Supermicro BMC web UI user management (cgi/config_user.cgi, X10DRH-iT): An attacker who gets a logged-in BMCCVE-2020-15046 · Supermicro BMC web UI user management (cgi/config_user.cgi, X10DRH-iT)High
- ipmitool (IPMI LAN response parsing): Reverses the usual direction of BMC risk: here the management stationCVE-2020-5208 · ipmitool (IPMI LAN response parsing)High
- Cisco NX-OS / FXOS (Cisco Discovery Protocol): Root code execution on the switch from a crafted CDP frame sentCVE-2022-20824 · Cisco NX-OS / FXOS (Cisco Discovery Protocol)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.