Database/Firmware, BMC & network fabric

AMI MegaRAC SPx (Dynamic Redfish Extension): Code injection executed via the Dynamic Redfish Extension interface
CVSS 8.2CVE-2023-34330Firmware, BMC & network fabriccurated
Impact
Code injection executed via the Dynamic Redfish Extension interface; BMC-level code execution
Who can reach it
Network / Redfish, authenticated-adjacent
What to do
Same BMC flash cycle as CVE-2023-34329; ODM rebase required, cannot be mitigated in the host OS
References
Related entries
- Signed third-party UEFI application (Howyar Reloader and OEM rebrands): A Microsoft-signed UEFI recovery applicationCVE-2024-7344 · Signed third-party UEFI application (Howyar Reloader and OEM rebrands)High
- Insyde InsydeH2O (H19Int15CallbackSmm, combined DXE/SMM driver): An unchecked output buffer in a combined DXE/SMMCVE-2025-10451 · Insyde InsydeH2O (H19Int15CallbackSmm, combined DXE/SMM driver)High
- Intel Server Firmware Update Utility (SysFwUpdt) and Server Configuration Utility before version 16.0.12: ImproperCVE-2025-25210 · Intel Server Firmware Update Utility (SysFwUpdt) and Server Configuration Utility before version 16.0.12High
- AMI AptioV UEFI BIOS (SMM): A write-what-where primitive plus an information leak in System Management ModeCVE-2025-33045 · AMI AptioV UEFI BIOS (SMM)High
- Broadcom NetXtreme-E network adapter firmware: A high-severity flaw in the firmware of Broadcom NetXtreme-E adaptersCVE-2025-56547 · Broadcom NetXtreme-E network adapter firmwareHigh
- IBM Power Systems Firmware: BMC/FSP-to-host interface allows arbitrary code execution on the host systemCVE-2026-16930 · IBM Power Systems Firmware (BMC/FSP-to-host interface)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.