Database/Firmware, BMC & network fabric

AMI MegaRAC SPx12 (BMC&C): Auth bypass by spoofing the HTTP header
Impact
Auth bypass by spoofing the HTTP header; combined with CVE-2023-34330 gives unauthenticated RCE as root on the BMC. Below-OS persistence
Who can reach it
Network, BMC web/Redfish
What to do
BMC firmware update per node via ODM build; combined-chain risk means treat as critical even where the BMC is on a management VLAN
Fleet impact
How widespread
universal - same MegaRAC OEM footprint
Cost to remediate
firmware-flash - full BMC image update per node, out-of-band, cannot run while a tenant job holds the host
Why it hits the whole fleet
Chaining the HTTP-header auth spoof with the code-injection primitive yields pre-OS code execution on the BMC; identical firmware across a homogeneous GPU fleet means one exploit works on every node.
References
Related entries
- Arista EOS (secure VXLAN / Tunnelsec agent): After the Tunnelsec agent restarts, traffic that should be encryptedCVE-2024-12378 · Arista EOS (secure VXLAN / Tunnelsec agent)Critical
- Software House iSTAR door controllers (firmware before 6.6.B) and the IP-ACM Ethernet Door Module link: The iSTARCVE-2024-32752 · Software House iSTAR door controllers (firmware before 6.6.B) and the IP-ACM Ethernet Door Module linkCritical
- The IPMI 2.0 authenticated-session mechanism as specified and as implemented across multiple vendors: An attackerCVE-2024-3411 · The IPMI 2.0 authenticated-session mechanism as specified and as implemented across multiple vendorsCritical
- Dell Enterprise SONiC (OS command injection): OS command injection giving arbitrary command execution on the switch'sCVE-2024-45763 · Dell Enterprise SONiC (OS command injection)Critical
- Dell Enterprise SONiC (privilege boundary in CLI): High-privilege OS commands can be run by users holding lessCVE-2024-45765 · Dell Enterprise SONiC (privilege boundary in CLI)Critical
- Arista EOS (OpenConfig gNOI authorization): The gNOI equivalent of the gNMI authorization bypass: operationsCVE-2025-1260 · Arista EOS (OpenConfig gNOI authorization)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.