Database/Firmware, BMC & network fabric
Tyan S5552 BMC web interface, firmware version 3.00: An unauthenticated attacker downloads the BMC's TLS private key
Impact
An unauthenticated attacker downloads the BMC's TLS private key. With it they can decrypt captured management traffic and impersonate the BMC to your own tooling - meaning your provisioning system, monitoring collector and operators can be fed a controller that is not the controller, and will hand over BMC credentials to it. Because vendors frequently ship the same certificate across a production run, a key pulled from one Tyan S5552 may authenticate an impersonated BMC across every node of that model in the fleet. That turns a medium-scored file disclosure into a fleet-wide management-plane credential harvest. The private key for the TLS certificate the BMC presents is retrievable by forced browsing, with no authentication.
Who can reach it
Unauthenticated HTTP access to the BMC web interface - anything routable to the out-of-band management VLAN. No credential and no host foothold required.
What to do
Firmware update from Tyan, and this is where an operator hits a wall: Tyan has been folded into MiTAC Computing, www.tyan.com no longer presents a valid TLS certificate for its own hostname, and mitaccomputing.com returns 403 to automated clients - so there is no reachable vendor PSIRT to obtain a fixed image from. The advisory that exists is third-party, from Nozomi Networks. Regardless of firmware state, replace the BMC's TLS certificate with one you generated and control, and rotate any BMC credentials that were transmitted to that BMC over a session an attacker could have decrypted. Certificate replacement is a config-only change and should be done on every BMC in the fleet as standard practice, not just Tyan ones.
References
Related entries
- Dell iDRAC Service Module (out-of-bounds write): Out-of-bounds write allowing a privileged local attacker to executeCVE-2024-38490 · Dell iDRAC Service Module (out-of-bounds write)Medium
- EDK2: BIOS exposes sensitive information to a local unauthorized actorCVE-2024-38798 · TianoCore EDK2 (BIOS)Medium
- Arista EOS (PBR / BGP Flowspec / interface traffic policy): IPv4 packets carrying IP options can bypass policy-basedCVE-2024-6437 · Arista EOS (PBR / BGP Flowspec / interface traffic policy)Medium
- AMI AptioV UEFI BIOS: Improper input validation in the BIOS with an integrity impact and a changed scopeCVE-2025-33043 · AMI AptioV UEFI BIOSMedium
- Arista EOS (tunnel decapsulation): With VXLAN, decap-groups or GRE configured, the switch incorrectly decapsulates andCVE-2026-7473 · Arista EOS (tunnel decapsulation)Medium
- GRUB2 (initrd size handling): Integer overflows in the initrd command's size arithmetic corrupt GRUB's heapCVE-2020-15707 · GRUB2 (initrd size handling)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.