Database/Firmware, BMC & network fabric

AMI MegaRAC SPx12/SPx13: Insufficient verification of data authenticity — firmware image signature can be subverted
CVSS 9.1CVE-2023-28863Firmware, BMC & network fabriccurated
Impact
Insufficient verification of data authenticity — firmware image signature can be subverted; enables persistent implant
Who can reach it
Local/network firmware update path
What to do
BMC flash; also requires operational control so that only signed, vendor-verified images reach the update endpoint
References
Related entries
- CyberPower PowerPanel Enterprise DCIM - remote backup location username field: OS command injection throughCVE-2023-3267 · CyberPower PowerPanel Enterprise DCIM - remote backup location username fieldCritical
- AMI MegaRAC SPx12 (BMC&C): Auth bypass by spoofing the HTTP headerCVE-2023-34329 · AMI MegaRAC SPx12 (BMC&C)Critical
- Arista EOS (secure VXLAN / Tunnelsec agent): After the Tunnelsec agent restarts, traffic that should be encryptedCVE-2024-12378 · Arista EOS (secure VXLAN / Tunnelsec agent)Critical
- Software House iSTAR door controllers (firmware before 6.6.B) and the IP-ACM Ethernet Door Module link: The iSTARCVE-2024-32752 · Software House iSTAR door controllers (firmware before 6.6.B) and the IP-ACM Ethernet Door Module linkCritical
- The IPMI 2.0 authenticated-session mechanism as specified and as implemented across multiple vendors: An attackerCVE-2024-3411 · The IPMI 2.0 authenticated-session mechanism as specified and as implemented across multiple vendorsCritical
- Dell Enterprise SONiC (OS command injection): OS command injection giving arbitrary command execution on the switch'sCVE-2024-45763 · Dell Enterprise SONiC (OS command injection)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.