Database/Firmware, BMC & network fabric

AMI MegaRAC SPx 12 / SPx 13 (BMC): Untrusted pointer dereference in the BMC that a low-privileged actor can turn
Impact
Untrusted pointer dereference in the BMC that a low-privileged actor can turn into code execution or a controller crash. As a second-stage bug it is how an attacker who already got a foothold - a read-only monitoring account, a low-privilege Redfish user, or a partial exploit of one of the network bugs - upgrades to full BMC control and firmware persistence.
Who can reach it
AMI's CVSS vector scores this as local access with low privileges required, while AMI's own prose calls it reachable from the local network; treat it as reachable by anyone who already holds a low-privilege position on or adjacent to the BMC. In a fleet, the realistic precondition is a leaked low-tier BMC credential - which is common, because BMC passwords are frequently shared across a whole rack or SKU by the provisioning system.
What to do
Firmware flash to SPx_12.7 / SPx_13.6, out-of-band per node, ODM-gated. Alongside the flash, the cheap wins are config-only: give every BMC a unique password (kill any shared default from the deployment template), delete unused BMC accounts, and drop any monitoring account down to the minimum Redfish role.
References
Related entries
- AMI MegaRAC SPx (untrusted pointer dereference): Untrusted pointer dereference in the BMC allowing a local-networkCVE-2023-34333 · AMI MegaRAC SPx (untrusted pointer dereference)High
- Supermicro X12DPG-QR BIOS 1.4b: Control-flow hijack inside platform firmware, driven by an NVRAM variableCVE-2023-34853 · Supermicro X12DPG-QR BIOS 1.4bHigh
- Dell SmartFabric Storage Software (restricted shell in SSH): OS command injection escaping the restricted shell of theCVE-2023-43068 · Dell SmartFabric Storage Software (restricted shell in SSH)High
- GRUB2 (NTFS filesystem parser): Out-of-bounds write parsing a crafted NTFS volumeCVE-2023-4692 · GRUB2 (NTFS filesystem parser)High
- Phoenix SecureCore Technology 4 (boot splash screen image parsing): The firmware parses a user-supplied boot logo imageCVE-2023-5058 · Phoenix SecureCore Technology 4 (boot splash screen image parsing)High
- Linux kernel (drivers/infiniband/hw/hfi1): User SDMA requests with multiple payload buffers are read past the declaredCVE-2023-52474 · Linux kernel (drivers/infiniband/hw/hfi1)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.