Database/Firmware, BMC & network fabric

Intel Server OpenBMC firmware (before egs-1.09) - authentication logic: An authenticated low-privilege user escalates
Impact
An authenticated low-privilege user escalates privilege on the BMC, with a scope change - the escalation crosses a security boundary rather than staying inside the account model. On fleets that hand out constrained BMC accounts to tenants, support staff or monitoring systems (read-only sensor scraping is a common one), this converts any of those accounts into something with more control over the node. The lesson for a GPU operator: a read-only BMC account issued to a customer or a monitoring vendor is not a safe thing to hand out on this firmware.
Who can reach it
Local access with a low-privileged authenticated BMC account. Needs an existing credential, so exposure tracks how widely you distribute BMC accounts.
What to do
Fixed in Intel Server OpenBMC egs-1.09 and later; delivery is a per-node out-of-band BMC firmware update through Intel's platform packages, with the usual OEM rebase lag on non-Intel-badged boards using the same base. Config-only compensation: stop issuing BMC accounts to third parties, proxy sensor and telemetry reads through your own collector rather than giving monitoring vendors direct BMC credentials.
References
Related entries
- Cisco NX-OS (bootloader / image signature verification): Secure boot on the switch is defeatable: an attackerCVE-2024-20397 · Cisco NX-OS (bootloader / image signature verification)Medium
- AMI AptioV UEFI BIOS (SPI flash integrity verification): An actor with physical access can modify the SPI flashCVE-2024-33660 · AMI AptioV UEFI BIOS (SPI flash integrity verification)Medium
- shim (MZ/PE header parser): Out-of-bounds read parsing MZ binariesCVE-2023-40551 · shim (MZ/PE header parser)Medium
- Solidigm DC SSDs (D3-S4510/S4520/S4610/S4620, D5-P5316, D7-P5520/P5620, DC S4500/S4600)CVE-2024-47973 · Solidigm DC SSDs (D3-S4510/S4520/S4610/S4620, D5-P5316, D7-P5520/P5620, DC S4500/S4600) - over-provisioned NAND not…Medium
- Arm Neoverse V2 / V3 / V3AE, Cortex-X3 / X4 / X925, C1-seriesCVE-2024-7881 · Arm Neoverse V2 / V3 / V3AE, Cortex-X3 / X4 / X925, C1-series; mitigated in Trusted Firmware-A v2.2-v2.12 and LTS…Medium
- Junos Space: stored XSS in management UI pages lets an attacker run actions as a logged-in administratorCVE-2025-59990 · Juniper Junos Space (template creation and report generation pages)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.