Database/Firmware, BMC & network fabric

AMI MegaRAC: Default credentials for the `sysadmin` account, shell access to the BMC
CVSS 7.5CVE-2022-40242Firmware, BMC & network fabriccurated
Impact
Default credentials for the sysadmin account, shell access to the BMC
Who can reach it
Network / SSH to BMC
What to do
Same intake-time credential rotation; add a fleet scan asserting no default BMC accounts remain
References
Related entries
- AMI MegaRAC: Weak MD5 password hashing for BMC accountsCVE-2022-40258 · AMI MegaRACMedium
- AMI MegaRAC: Password reset interception via the API — attacker takes over an admin BMC accountCVE-2022-26872 · AMI MegaRACHigh
- AMI MegaRAC: Default credentials — Redfish API accessible with shipped accountCVE-2022-40259 · AMI MegaRACHigh
- AMI MegaRAC: User enumeration — lets an attacker map valid BMC accounts before credential attackCVE-2022-2827 · AMI MegaRACHigh
- Linux kernel (drivers/infiniband/hw/irdma): A permanent kernel hang once any queue-pair goes to error.CVE-2022-48694 · Linux kernel (drivers/infiniband/hw/irdma)High
- Linux kernel (drivers/infiniband/sw/siw): A remote peer crashes the node during connection setup. When the MPACVE-2022-50136 · Linux kernel (drivers/infiniband/sw/siw)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.