Database/Firmware, BMC & network fabric

ASPEED AST2400 / AST2500 BMC SoC: Arbitrary read/write of the BMC's entire physical address space **from the host CPU**
Impact
Arbitrary read/write of the BMC's entire physical address space **from the host CPU** — host-to-BMC boundary collapse. A tenant with host root can implant the BMC; survives reimaging and node reallocation
Who can reach it
Local, from the host OS via iLPC2AHB / PCIe VGA / X-DMA bridges
What to do
Fix is a BMC firmware build that disables the AHB bridges (OpenBMC has it; many ODM builds do not). On multi-tenant bare metal this is the single most important control — otherwise every tenant handoff is a potential persistent implant
Fleet impact
How widespread
universal - ASPEED is effectively the sole-source BMC SoC in x86 server boards, including GPU servers
Cost to remediate
firmware-flash per node; on some boards the only mitigation is disabling the LPC/PCIe P2A bridges in an OEM image respin, and several SKUs remain unpatchable-mitigate-only
Why it hits the whole fleet
Host-side root can read/write the BMC's entire physical address space over LPC/PCIe, so any tenant that gets host root pivots into the always-on management processor - below the hypervisor, persistent across reimaging, on every node of an ASPEED-based fleet.
References
Related entries
- NVIDIA DGX BMC (AMI firmware): Hard-coded credentials in the DGX BMC firmwareCVE-2020-11483 · NVIDIA DGX BMC (AMI firmware)Critical
- NVIDIA DGX BMC (AMI firmware): File upload into the BMC that gets automatically processed, yielding remote codeCVE-2020-11486 · NVIDIA DGX BMC (AMI firmware)Critical
- Rittal PDU-3C002DEC rack PDU firmware (through 5.17.10): A backdoor root account in the PDU firmware. Not a weakCVE-2020-11951 · Rittal PDU-3C002DEC rack PDU firmware (through 5.17.10)Critical
- Rittal PDU-3C002DEC rack PDU firmware (through 5.17.10): Least-privilege violation: low-privilege users on the PDU getCVE-2020-11956 · Rittal PDU-3C002DEC rack PDU firmware (through 5.17.10)Critical
- Dell iDRAC9: Stack-based buffer overflow via crafted remote input — pre-auth code execution on the BMCCVE-2020-5344 · Dell iDRAC9Critical
- APC Easy UPS On-Line Software (SFAPV9601) FileUploadServlet: Path traversal in a file upload servlet allows writingCVE-2020-7521 · APC Easy UPS On-Line Software (SFAPV9601) FileUploadServletCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.