Database/Firmware, BMC & network fabric
NVIDIA DGX BMC (AMI-derived management controller): The DGX-1 BMC's SPX REST API accepts injected shell commands
Impact
The DGX-1 BMC's SPX REST API accepts injected shell commands from an authorised caller, giving direct command execution on the management controller. A BMC compromise on a DGX gives an attacker power control, virtual media, serial console and a persistent foothold under the host OS on a node holding eight GPUs.
Who can reach it
Network access to the BMC management interface holding credentials at some authorised level. Whether that is 'remote' depends entirely on how genuinely isolated your OOB network is - in practice most fleets have a jump host, a DCIM integration or a monitoring collector that bridges it.
What to do
Update the DGX BMC firmware bundle per bulletin 5458. Cost: BMC firmware usually updates without draining the GPUs, but the BMC resets and out-of-band access drops for a few minutes. Pair the patch with an actual audit of who can route to the BMC subnet - that control is worth more than the patch.
References
Related entries
- NVIDIA DGX BMC (AMI-derived management controller): The DGX-1 BMC's IPMI handler allows an authorised attackerCVE-2023-25508 · NVIDIA DGX BMC (AMI-derived management controller)Medium
- NVIDIA DGX BMC (AMI-derived management controller): The BMC's SPX REST API lets an authorised attacker read and writeCVE-2022-42278 · NVIDIA DGX BMC (AMI-derived management controller)High
- AMD Power Management Firmware (PMFW) - unintended proxy to the System Management Unit: The GPU power managementCVE-2023-31313 · AMD Power Management Firmware (PMFW) - unintended proxy to the System Management UnitHigh
- Dataprobe iBoot PDU: Authenticated OS command injection on the PDUCVE-2023-3260 · Dataprobe iBoot PDUHigh
- Intel 4th Gen Xeon on-chip debug and test interface (with SGX or TDX): The on-chip debug and test interface hasCVE-2023-32666 · Intel 4th Gen Xeon on-chip debug and test interface (with SGX or TDX)High
- AMI MegaRAC SPx (SPX REST API): Arbitrary read and write into the memory of the BMC's IPMI server process via the SPXCVE-2023-34341 · AMI MegaRAC SPx (SPX REST API)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.