Database/Firmware, BMC & network fabric
NVIDIA DGX BMC (AMI firmware): The PRNG used by the IPMI implementation in the BMC's JSOL package
Impact
The PRNG used by the IPMI implementation in the BMC's JSOL package is not cryptographically strong, so session identifiers and other 'random' values are predictable. Combined with the rest of this bulletin it removes the guesswork from hijacking BMC/IPMI sessions. DGX-1 before BMC 3.38.30.
Who can reach it
Anyone with network reach to the BMC's IPMI service.
What to do
Flash the DGX BMC firmware from NVIDIA's DGX firmware update container (DGX-1 to 3.38.30 or later, DGX-2 to 1.06.06 or later; DGX A100 per the bulletin's table). A BMC flash does not require the host OS to reboot but drops out-of-band management for several minutes and NVIDIA recommends a host power cycle afterwards, so treat it as a per-node maintenance window. Rotate every BMC and IPMI credential after the flash - flashing does not invalidate secrets an attacker already pulled. Keep BMCs on an isolated management VLAN with no route from tenant or job networks.
References
Related entries
- NVIDIA DGX BMC (AMI firmware): The BMC does not validate the RSA-1024 public key used to verify firmware signaturesCVE-2020-11488 · NVIDIA DGX BMC (AMI firmware)Medium
- NVIDIA DGX BMC (AMI firmware): An administrative BMC user can pull the hash of the BMC/IPMI user passwordCVE-2020-11484 · NVIDIA DGX BMC (AMI firmware)Medium
- NVIDIA DGX BMC (AMI firmware): Hard-coded credentials in the DGX BMC firmwareCVE-2020-11483 · NVIDIA DGX BMC (AMI firmware)Critical
- NVIDIA DGX BMC (AMI firmware): File upload into the BMC that gets automatically processed, yielding remote codeCVE-2020-11486 · NVIDIA DGX BMC (AMI firmware)Critical
- NVIDIA DGX BMC (AMI firmware): CSRF in the BMC web applicationCVE-2020-11485 · NVIDIA DGX BMC (AMI firmware)High
- NVIDIA DGX BMC (AMI firmware): A hard-coded RSA-1024 key with weak ciphers in the BMC firmware means the encryptionCVE-2020-11487 · NVIDIA DGX BMC (AMI firmware)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.