Database/Firmware, BMC & network fabric

AMI MegaRAC SPx 12 / SPx 13 (BMC login): The login flow answers differently for real and fake usernames, so
Impact
The login flow answers differently for real and fake usernames, so an unauthenticated attacker can enumerate every valid BMC account. The value to an attacker is targeting: sweep the management range, learn which nodes still carry the ODM's default account or the provisioning template's service account, and aim credential-stuffing only at those. It turns a noisy brute-force into a quiet, low-attempt campaign that will not trip lockout thresholds.
Who can reach it
Unauthenticated network access to the BMC web login. Anything that can reach the BMC's HTTP/HTTPS port on the management VLAN.
What to do
Firmware flash to SPx_12-update-7.00 / SPx_13-update-5.00 or later; low urgency on its own, fold it into whatever BMC flash campaign you are already running. The config-only work carries most of the value and costs nothing: delete vendor default accounts, avoid a fleet-wide shared username in the provisioning template, and enable BMC account lockout plus authentication logging to your SIEM so the enumeration sweep itself becomes visible.
References
Related entries
- AMI MegaRAC: Weak MD5 password hashing for BMC accountsCVE-2022-40258 · AMI MegaRACMedium
- AMD IOMMU - nested page table entry faults bypass SEV-SNP RMP checks: The IOMMU mishandles invalid nested page tableCVE-2023-20582 · AMD IOMMU - nested page table entry faults bypass SEV-SNP RMP checksMedium
- AMD IOMMU - invalid device table entries bypass SEV-SNP RMP checks: The IOMMU mishandles certain special address rangesCVE-2023-20584 · AMD IOMMU - invalid device table entries bypass SEV-SNP RMP checksMedium
- AMI MegaRAC SPX (Redfish): User enumeration through RedfishCVE-2023-25192 · AMI MegaRAC SPX (Redfish)Medium
- Insyde InsydeH2O (TrEEConfigDriver, TPM PCR reporting): Low CVSS, high operational consequenceCVE-2023-30633 · Insyde InsydeH2O (TrEEConfigDriver, TPM PCR reporting)Medium
- Intel Server OpenBMC firmware (before egs-1.05) - credential storage: Credentials are insufficiently protectedCVE-2023-32280 · Intel Server OpenBMC firmware (before egs-1.05) - credential storageMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.