Database/Firmware, BMC & network fabric
Supermicro BMC web server on X11 and M11 based boards with firmware up to 3.17.02: An unauthenticated attacker reads
Impact
An unauthenticated attacker reads files out of the BMC's filesystem. In practice that is the credential store, configuration, and keys - which is how this becomes the first link in a chain rather than an information-disclosure footnote: the traversal hands over the credentials needed to exploit CVE-2023-33412 and CVE-2023-33413 on the same box, and because BMC credentials are typically identical across a fleet, one node's disclosure unlocks all of them. Directory traversal in the HTTP server, reachable with no authentication whatsoever.
Who can reach it
Anything routable to the BMC's HTTP interface, unauthenticated. No credential, no host foothold, no tenant access needed - only a network path to the out-of-band management VLAN.
What to do
Firmware flash to BMC 3.17.02 or later per board, from Supermicro's December 2023 advisory. Because this one needs no credentials, it should be at the front of the queue for any X11 fleet, and any node that was ever exposed to an untrusted network should have its BMC credentials treated as compromised and rotated - to unique per-node values, not another shared password. Network isolation buys time but does not help if your management VLAN is flat and reachable from tenant hosts.
References
Related entries
- Juniper Junos OS PFE on QFX10000 Series (VXLAN tunnel routing): A specific *valid* IP packet that needs to be routedCVE-2023-36835 · Juniper Junos OS PFE on QFX10000 Series (VXLAN tunnel routing)High
- UEFI image parsers, AMI AptioV: Unrestricted upload of a crafted BMP logo parsed by the BIOS at bootCVE-2023-39538 · UEFI image parsers, AMI AptioVHigh
- UEFI image parsers, AMI AptioV: Second LogoFAIL image-parser flaw in AMI AptioV BIOSCVE-2023-39539 · UEFI image parsers, AMI AptioVHigh
- Juniper Junos OS Packet Forwarding Engine (MX Series): Improper handling of unusual conditions in the Packet ForwardingCVE-2023-44199 · Juniper Junos OS Packet Forwarding Engine (MX Series)High
- AMI AptioV UEFI BIOS (EDK II network stack, IPv6): An infinite loop when the firmware parses unknown options in an IPv6CVE-2023-45232 · AMI AptioV UEFI BIOS (EDK II network stack, IPv6)High
- EDK II NetworkPkg (IPv6 Destination Options header, PadN option parsing): Same shape as the unknown-option hang butCVE-2023-45233 · EDK II NetworkPkg (IPv6 Destination Options header, PadN option parsing)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.