Database/Firmware, BMC & network fabric

IBM OpenBMC OP910 web UI (phosphor-webui lineage): Stored/reflected script injection in the BMC web interface
Impact
Stored/reflected script injection in the BMC web interface. The victim is your own operator: an admin opens the BMC console and the injected script runs with their authenticated session, which is a session that can power-cycle nodes, mount virtual media and push firmware. On a GPU fleet the practical scenario is an attacker who has read-only or low-privilege access to one BMC planting the payload and waiting for an administrator to visit, converting a foothold into administrative control without ever cracking a password.
Who can reach it
Requires getting attacker-controlled content into a field the BMC web UI renders, plus an administrator subsequently loading that page. Network access to the BMC web interface.
What to do
Fixed in later OP910 firmware - per-node system firmware update, maintenance window. Cheap compensating control: do not browse BMC web UIs from the same browser profile you use for anything else, and prefer Redfish API calls over the web UI for routine operations. Fleet-scale automation against Redfish rather than humans clicking through per-node web UIs removes the victim this bug needs.
References
Related entries
- Intel 3rd/4th Gen Xeon with SGX or TDX (protection mechanism failure): A protection mechanism in 3rd and 4th generationCVE-2023-22655 · Intel 3rd/4th Gen Xeon with SGX or TDX (protection mechanism failure)Medium
- shim (mok.c mirror_one_esl): NULL pointer dereference while printing an error message stops the node from bootingCVE-2023-40546 · shim (mok.c mirror_one_esl)Medium
- Linux kernel (drivers/pci/switch): If a userspace process is holding the Switchtec management character device openCVE-2023-52617 · Linux kernel (drivers/pci/switch)Medium
- Avocent DSR2030 / SVIP1020 KVM-over-IP appliance: A reflected XSS in the appliance's web interface lets an attackerCVE-2024-34923 · Avocent DSR2030 / SVIP1020 KVM-over-IP applianceMedium
- Intel Xeon 6 E-core with TDX or SGX: Improper restriction of software interfaces to hardware features on Xeon 6 E-coreCVE-2024-48869 · Intel Xeon 6 E-core with TDX or SGXMedium
- Intel Ethernet E810 Series and Ethernet 700 Series firmware: Out-of-bounds write in firmware across both the E810 lineCVE-2022-36382 · Intel Ethernet E810 Series and Ethernet 700 Series firmwareMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.