Database/Firmware, BMC & network fabric

AMI MegaRAC SPx (Redfish): Password disclosure through Redfish
CVSS 7.5CVE-2023-25191Firmware, BMC & network fabriccurated
Impact
Password disclosure through Redfish; credentials frequently reused across a whole fleet of identically-provisioned nodes
Who can reach it
Network / Redfish
What to do
Firmware update to SPx_12-update-7.00 / SPx_13-update-5.00 plus a fleet-wide BMC credential rotation
References
Related entries
- AMI MegaRAC SPx 12 (Service Location Protocol service): Every BMC running SLP is a free DDoS cannon pointedCVE-2023-29552 · AMI MegaRAC SPx 12 (Service Location Protocol service)High
- Supermicro BMC web server on X11 and M11 based boards with firmware up to 3.17.02: An unauthenticated attacker readsCVE-2023-33411 · Supermicro BMC web server on X11 and M11 based boards with firmware up to 3.17.02High
- Juniper Junos OS PFE on QFX10000 Series (VXLAN tunnel routing): A specific *valid* IP packet that needs to be routedCVE-2023-36835 · Juniper Junos OS PFE on QFX10000 Series (VXLAN tunnel routing)High
- UEFI image parsers, AMI AptioV: Unrestricted upload of a crafted BMP logo parsed by the BIOS at bootCVE-2023-39538 · UEFI image parsers, AMI AptioVHigh
- UEFI image parsers, AMI AptioV: Second LogoFAIL image-parser flaw in AMI AptioV BIOSCVE-2023-39539 · UEFI image parsers, AMI AptioVHigh
- Juniper Junos OS Packet Forwarding Engine (MX Series): Improper handling of unusual conditions in the Packet ForwardingCVE-2023-44199 · Juniper Junos OS Packet Forwarding Engine (MX Series)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.