Database/Firmware, BMC & network fabric

AMI MegaRAC SPx12/SPx13: Insufficient verification of data authenticity — firmware image signature can be subverted
CVE-2023-28863Firmware, BMC & network fabriccurated
Impact
Insufficient verification of data authenticity — firmware image signature can be subverted; enables persistent implant
Who can reach it
Local/network firmware update path
What to do
BMC flash; also requires operational control so that only signed, vendor-verified images reach the update endpoint
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.