Database/Firmware, BMC & network fabric

Dataprobe iBoot PDU: Authenticated OS command injection on the PDU
CVSS 7.2CVE-2023-3260Firmware, BMC & network fabriccurated
Impact
Authenticated OS command injection on the PDU — an attacker who reaches the power controller can cut power to racks, and can pivot from the PDU into the management network
Who can reach it
Network, authenticated
What to do
PDU firmware update to 1.44.08042023; PDUs are rarely in the patch pipeline at all, so the real cost is building one
References
Related entries
- Intel 4th Gen Xeon on-chip debug and test interface (with SGX or TDX): The on-chip debug and test interface hasCVE-2023-32666 · Intel 4th Gen Xeon on-chip debug and test interface (with SGX or TDX)High
- AMI MegaRAC SPx (SPX REST API): Arbitrary read and write into the memory of the BMC's IPMI server process via the SPXCVE-2023-34341 · AMI MegaRAC SPx (SPX REST API)High
- AMI MegaRAC SPx (SPX REST API): Shell command injection through the BMC's REST APICVE-2023-34343 · AMI MegaRAC SPx (SPX REST API)High
- Supermicro BMC (IPMI web interface, command injection): Command injection that turns a BMC administrator accountCVE-2023-40289 · Supermicro BMC (IPMI web interface, command injection)High
- Dell PowerEdge Server BIOS (SMM communication buffer): The BIOS fails to properly validate the SMM communicationCVE-2024-0161 · Dell PowerEdge Server BIOS (SMM communication buffer)High
- Supermicro BMC firmware validation (MBD-X12DPG-OA6): Root-of-Trust bypassCVE-2024-10237 · Supermicro BMC firmware validation (MBD-X12DPG-OA6)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.