Database/Firmware, BMC & network fabric

AMI MegaRAC SPx 12 (BMC default TLS certificate): The BMC ships with a hard-coded default TLS certificate, so HTTPS
Impact
The BMC ships with a hard-coded default TLS certificate, so HTTPS to the management interface can be transparently intercepted by anyone holding the extracted key - which is everyone, since it is identical across all devices built from that firmware. The operator loses exactly what they thought they were buying with HTTPS: BMC admin passwords, Redfish tokens and KVM traffic are readable to an attacker who can sit in the path. Because the same certificate is on every node, a single extraction compromises the whole management plane.
Who can reach it
Requires a man-in-the-middle position on the management network - a compromised jump host, a rogue device on the management VLAN, or control of a switch or DHCP server on that segment. No credentials needed. Disclosed by Nozomi Labs against a Lanner IAC-AST2500A platform; AMI's own advisory confirms the affected code is part of MegaRAC SPx, so the exposure is not limited to that one vendor's box.
What to do
Firmware flash to SPx_12-update-3.00 or later (AMI states SPx_13 is not affected), but flashing alone does not fix a node whose certificate is already installed. The operative fix is config-only and can be done today across the fleet without a reboot: generate a unique certificate per BMC from your own internal CA and push it over Redfish, then have your management tooling actually pin or verify it rather than skipping certificate validation - which is the default in most homegrown BMC scrapers and is the reason this bug stays exploitable.
References
Related entries
- AMI MegaRAC SPx 12 / SPx 13 (BMC web session management): Session fixation combined with sessions that never properlyCVE-2021-46279 · AMI MegaRAC SPx 12 / SPx 13 (BMC web session management)Medium
- Tyan S5552 BMC web interface, firmware version 3.00: An unauthenticated attacker downloads the BMC's TLS private keyCVE-2023-2538 · Tyan S5552 BMC web interface, firmware version 3.00Medium
- Dell iDRAC Service Module (out-of-bounds write): Out-of-bounds write allowing a privileged local attacker to executeCVE-2024-38490 · Dell iDRAC Service Module (out-of-bounds write)Medium
- EDK2: BIOS exposes sensitive information to a local unauthorized actorCVE-2024-38798 · TianoCore EDK2 (BIOS)Medium
- Arista EOS (PBR / BGP Flowspec / interface traffic policy): IPv4 packets carrying IP options can bypass policy-basedCVE-2024-6437 · Arista EOS (PBR / BGP Flowspec / interface traffic policy)Medium
- AMI AptioV UEFI BIOS: Improper input validation in the BIOS with an integrity impact and a changed scopeCVE-2025-33043 · AMI AptioV UEFI BIOSMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.