Database/Firmware, BMC & network fabric

AMI MegaRAC SPx 12 / SPx 13 (BMC web session management): Session fixation combined with sessions that never properly
Impact
Session fixation combined with sessions that never properly expire. An attacker can plant a session identifier, wait for an administrator to authenticate with it, and inherit a live admin session on the BMC - power control, console, virtual media, firmware update. The never-expiring half means stolen sessions stay valid long after the admin walked away, so a token lifted from a browser, a proxy log or a shared jump host keeps working for as long as the attacker wants it.
Who can reach it
Network access to the BMC web interface plus getting an administrator to interact with an attacker-supplied session - a link, a shared workstation, or a proxy on the management path. High complexity, no credentials required.
What to do
Firmware flash to SPx_12-update-7.00 / SPx_13-update-5.00 or later, out-of-band per node, ODM-gated. Config-only mitigations that help immediately: restrict BMC web access to a bastion, do not let admins browse anything else from that host, and force logout rather than closing the tab - the sessions this bug leaves behind are the ones that never got explicitly ended.
References
Related entries
- Tyan S5552 BMC web interface, firmware version 3.00: An unauthenticated attacker downloads the BMC's TLS private keyCVE-2023-2538 · Tyan S5552 BMC web interface, firmware version 3.00Medium
- Dell iDRAC Service Module (out-of-bounds write): Out-of-bounds write allowing a privileged local attacker to executeCVE-2024-38490 · Dell iDRAC Service Module (out-of-bounds write)Medium
- EDK2: BIOS exposes sensitive information to a local unauthorized actorCVE-2024-38798 · TianoCore EDK2 (BIOS)Medium
- Arista EOS (PBR / BGP Flowspec / interface traffic policy): IPv4 packets carrying IP options can bypass policy-basedCVE-2024-6437 · Arista EOS (PBR / BGP Flowspec / interface traffic policy)Medium
- AMI AptioV UEFI BIOS: Improper input validation in the BIOS with an integrity impact and a changed scopeCVE-2025-33043 · AMI AptioV UEFI BIOSMedium
- Arista EOS (tunnel decapsulation): With VXLAN, decap-groups or GRE configured, the switch incorrectly decapsulates andCVE-2026-7473 · Arista EOS (tunnel decapsulation)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.