Database/Firmware, BMC & network fabric

OpenBMC phosphor-net-ipmid (IPMI LAN+): Sibling finding to the authentication bypass, from the same Google report
Impact
Sibling finding to the authentication bypass, from the same Google report. Crafted IPMI messages take the BMC's IPMI daemon down without any credentials. Losing IPMI on its own is survivable if you run Redfish, but the operational shape is bad: an unauthenticated packet source on the management VLAN can knock out out-of-band management across every ASPEED node simultaneously, which is precisely when you would want it - during an incident, or to blind an operator while something else happens on the hosts.
Who can reach it
Unauthenticated, network, UDP 623 on the BMC. Same reachability precondition as the authentication bypass.
What to do
Same fix and same delivery cost as the authentication bypass: post-2.9 OpenBMC via a per-node out-of-band BMC firmware flash. Config-only mitigation is the same and is the right first move: turn off IPMI over LAN and run Redfish, or ACL UDP 623 to your management jump hosts. If you are already flashing for CVE-2021-39296 you get this one in the same image.
References
Related entries
- Linux kernel NVMe-oF RDMA target (nvmet-rdma error completion handling with shared CQ): After the switch to sharedCVE-2021-46983 · Linux kernel NVMe-oF RDMA target (nvmet-rdma error completion handling with shared CQ)High
- AMD SEV-SNP - VM_HSAVE_PA MSR validation: Insufficient validation of the VM_HSAVE_PA model-specific register lets aCVE-2022-23818 · AMD SEV-SNP - VM_HSAVE_PA MSR validationHigh
- OpenBMC bmcweb multipart_parser (Redfish / web UI HTTP front end): bmcweb is the single process behind Redfish, the webCVE-2022-2809 · OpenBMC bmcweb multipart_parser (Redfish / web UI HTTP front end)High
- AMI MegaRAC: User enumeration — lets an attacker map valid BMC accounts before credential attackCVE-2022-2827 · AMI MegaRACHigh
- Insyde InsydeH2O (UsbCoreDxe USB working buffer, DMA TOCTOU): UsbCoreDxe builds its USB transaction working bufferCVE-2022-30283 · Insyde InsydeH2O (UsbCoreDxe USB working buffer, DMA TOCTOU)High
- OpenBMC bmcweb multipart_parser (second variant found during the CVE-2022-2809 fix): The second bug the fuzzer foundCVE-2022-3409 · OpenBMC bmcweb multipart_parser (second variant found during the CVE-2022-2809 fix)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.