Database/Firmware, BMC & network fabric

AMI MegaRAC SPx 12 / SPx 13 (BMC TLS certificate generation): Malformed input to the BMC's certificate-generation
Impact
Malformed input to the BMC's certificate-generation function permanently wedges the controller, and the only documented recovery is a factory reset. On a GPU fleet that is worse than a normal DoS: you lose out-of-band power control, console and virtual media on the affected nodes, and getting them back means an on-site factory reset that also wipes your BMC configuration - accounts, certificates, network settings, alert destinations - so every affected node has to be re-provisioned by hand. A malicious insider or a compromised management account can do this across a rack in minutes and cost you days of remote-hands work.
Who can reach it
Network access to the BMC with high privileges - an administrative BMC account. Because BMC admin credentials are so often cloned across a fleet by the provisioning system, one leaked credential scales this to every node that shares it.
What to do
Firmware flash to SPx_12-update-5.00 / SPx_13-update-3.00 or later, out-of-band per node, ODM-gated. Config-only risk reduction: unique per-node BMC admin credentials so one leak cannot sweep the fleet, and - critically - keep an exported, version-controlled copy of every BMC's configuration so that if you do have to factory-reset, restoring is automated rather than a per-node manual rebuild.
References
Related entries
- IBM OpenBMC OP910 / OP940 certificate handling (phosphor-certificate-manager lineage): A privileged BMC userCVE-2022-22488 · IBM OpenBMC OP910 / OP940 certificate handling (phosphor-certificate-manager lineage)Medium
- Intel SPS firmware: Uncontrolled resource consumption in SPS firmware lets a privileged user deny serviceCVE-2023-29153 · Intel SPS firmwareMedium
- Dell PowerEdge Server BIOS + iDRAC9 (information disclosure): Information disclosure spanning both the BIOS and iDRAC9CVE-2025-26482 · Dell PowerEdge Server BIOS + iDRAC9 (information disclosure)Medium
- IBM OpenBMC: password supplied with a resource dump request is written to the BMC audit logCVE-2026-8058 · IBM OpenBMC (resource dump request handling, BMC audit log)Medium
- Lenovo XClarity Controller (XCC): Authorization bypassCVE-2019-6195 · Lenovo XClarity Controller (XCC)Medium
- ARM Trusted Firmware in AMD Zynq UltraScale+ MPSoC/RFSoC: Improper input validation in the ARM Trusted Firmware usedCVE-2023-31339 · ARM Trusted Firmware in AMD Zynq UltraScale+ MPSoC/RFSoCMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.