Database/Firmware, BMC & network fabric
Dell SmartFabric Storage Software: Improper input validation in Dell SmartFabric Storage Software 1.3 and lower
Impact
Improper input validation in Dell SmartFabric Storage Software 1.3 and lower, exploitable by a remote unauthenticated attacker. SmartFabric Storage Software is the NVMe-over-TCP fabric controller — it performs the discovery and zoning that decides which host initiators can see which NVMe subsystems. Compromising it is compromising the storage access-control layer for the whole cluster. Companion unauthenticated command injection: CVE-2022-31232.
Who can reach it
Unauthenticated, remote to the SmartFabric Storage Software service.
What to do
Upgrade the SmartFabric Storage Software appliance/VM past 1.3 (and past 1.4 for the CVE-2023-4306x set). Application upgrade with a service restart; NVMe-oF sessions reconnect. Afterwards, re-verify the zoning database against intent, because an attacker with control here would change exactly that.
References
Related entries
- CyberPower PowerPanel Enterprise DCIM - username handling: Authentication bypass: appending a non-printable characterCVE-2023-3265 · CyberPower PowerPanel Enterprise DCIM - username handlingCritical
- CyberPower PowerPanel Enterprise DCIM - LDAP authentication path: If LDAP authentication is selectedCVE-2023-3266 · CyberPower PowerPanel Enterprise DCIM - LDAP authentication pathCritical
- Supermicro BMC email/SMTP alert notification handler (H12DST-B): Command execution as root on the BMC, reached throughCVE-2023-35861 · Supermicro BMC email/SMTP alert notification handler (H12DST-B)Critical
- Juniper Junos OS J-Web (EX/SRX): Unauthenticated remote code execution by setting `PHPRC` through a crafted J-WebCVE-2023-36845 · Juniper Junos OS J-Web (EX/SRX)Critical
- Insyde InsydeH2O (AsfSecureBootDxe): Stack buffer overflow leading to arbitrary code execution during the DXE phaseCVE-2023-39281 · Insyde InsydeH2O (AsfSecureBootDxe)Critical
- lldpd (CDP PDU parser, cdp_decode): A crafted CDP PDU with specific CDP_TLV_ADDRESSES TLVs forces lldpdCVE-2023-41910 · lldpd (CDP PDU parser, cdp_decode)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.