GPU VulnDB

Database/Firmware, BMC & network fabric

AMI MegaRAC SPx12 (BMC&C): Auth bypass by spoofing the HTTP header

CVE-2023-34329Firmware, BMC & network fabriccurated

Impact

Auth bypass by spoofing the HTTP header; combined with CVE-2023-34330 gives unauthenticated RCE as root on the BMC. Below-OS persistence

Who can reach it

Network, BMC web/Redfish

What to do

BMC firmware update per node via ODM build; combined-chain risk means treat as critical even where the BMC is on a management VLAN

Fleet impact

How widespread

universal - same MegaRAC OEM footprint

Cost to remediate

firmware-flash - full BMC image update per node, out-of-band, cannot run while a tenant job holds the host

Why it hits the whole fleet

Chaining the HTTP-header auth spoof with the code-injection primitive yields pre-OS code execution on the BMC; identical firmware across a homogeneous GPU fleet means one exploit works on every node.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.