Database/Firmware, BMC & network fabric

ArubaOS-Switch (HPE Aruba wired switches): Remote arbitrary code execution on ArubaOS-Switch devices, affecting
Impact
Remote arbitrary code execution on ArubaOS-Switch devices, affecting every version of the 15.xx and early 16.xx trains. Aruba wired switches show up in GPU-cluster builds as the out-of-band management and provisioning fabric rather than the GPU data path — which makes RCE here a foothold on the network that reaches every BMC in the building.
Who can reach it
Remote to the switch's services. No credentials in the affected paths.
What to do
ArubaOS-Switch firmware upgrade plus switch reload. Management switches are usually not redundant the way the GPU fabric is, so a reload means the OOB network drops — schedule it when you do not need remote console. Restrict management-plane reachability first.
References
Related entries
- coreboot 4.13-4.16 (SMM handling on application processors): Arbitrary code execution in System Management ModeCVE-2022-29264 · coreboot 4.13-4.16 (SMM handling on application processors)Critical
- Ampere Altra and Altra Max UEFI reference design before SRP 1.09 - SMC interface exposing SPI-NOR flash: The OSCVE-2022-32295 · Ampere Altra and Altra Max UEFI reference design before SRP 1.09 - SMC interface exposing SPI-NOR flashCritical
- APC Easy UPS Online Monitoring Software (Windows and Windows Server): Critical functions in the UPS monitoring serverCVE-2022-42970 · APC Easy UPS Online Monitoring Software (Windows and Windows Server)Critical
- APC Easy UPS Online Monitoring Software (Windows and Windows Server): Unrestricted file upload leads to remote codeCVE-2022-42971 · APC Easy UPS Online Monitoring Software (Windows and Windows Server)Critical
- Ampere Altra and Altra Max before firmware 2.10c - PCIe root complex access control: The OS can re-initialise a PCIeCVE-2022-46892 · Ampere Altra and Altra Max before firmware 2.10c - PCIe root complex access controlCritical
- Linux SUNRPC / NFS-over-RDMA server (svc_rdma_build_writes): svc_rdma_build_writes can walk off the end of a WriteCVE-2022-49356 · Linux SUNRPC / NFS-over-RDMA server (svc_rdma_build_writes)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.