Database/Firmware, BMC & network fabric

APC Smart-UPS SMT/SMC/SMX/SCL/SMTL series - firmware update signing: Firmware images are signed with a key that leaked
Impact
Firmware images are signed with a key that leaked, so an attacker can flash arbitrary firmware onto the UPS and have it accepted as genuine. This is the worst of the three TLStorm bugs for an operator: the implant lives in the power device, survives every reimage of every server behind it, and is invisible to anything you run on the compute plane. An attacker who owns the UPS owns a kill switch for the racks it feeds, on a timer of their choosing.
Who can reach it
Network access to the UPS - either directly on the management network or via the intercepted cloud channel. Also reachable by anyone who can push a firmware image through the vendor's own update path.
What to do
Flash to fixed firmware, which changes the signing scheme. Because the compromise persists in firmware, patching alone does not prove cleanliness on a unit you believe was targeted - the honest answer there is re-flash from a known-good image and verify the reported firmware version out of band. Treat UPS firmware as part of your supply chain: version-inventory it, and refuse units that cannot report a verifiable firmware version.
References
Related entries
- AMI MegaRAC SPx12/SPx13: Insufficient verification of data authenticity — firmware image signature can be subvertedCVE-2023-28863 · AMI MegaRAC SPx12/SPx13Critical
- CyberPower PowerPanel Enterprise DCIM - remote backup location username field: OS command injection throughCVE-2023-3267 · CyberPower PowerPanel Enterprise DCIM - remote backup location username fieldCritical
- AMI MegaRAC SPx12 (BMC&C): Auth bypass by spoofing the HTTP headerCVE-2023-34329 · AMI MegaRAC SPx12 (BMC&C)Critical
- Arista EOS (secure VXLAN / Tunnelsec agent): After the Tunnelsec agent restarts, traffic that should be encryptedCVE-2024-12378 · Arista EOS (secure VXLAN / Tunnelsec agent)Critical
- Software House iSTAR door controllers (firmware before 6.6.B) and the IP-ACM Ethernet Door Module link: The iSTARCVE-2024-32752 · Software House iSTAR door controllers (firmware before 6.6.B) and the IP-ACM Ethernet Door Module linkCritical
- The IPMI 2.0 authenticated-session mechanism as specified and as implemented across multiple vendors: An attackerCVE-2024-3411 · The IPMI 2.0 authenticated-session mechanism as specified and as implemented across multiple vendorsCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.