Database/Firmware, BMC & network fabric

AMI MegaRAC SPx (untrusted pointer dereference): Untrusted pointer dereference in the BMC allowing a local-network
CVSS 7.8CVE-2023-34333Firmware, BMC & network fabriccurated
Impact
Untrusted pointer dereference in the BMC allowing a local-network attacker to compromise confidentiality, integrity and availability of the management processor.
Who can reach it
Local-network access to the BMC with low privilege.
What to do
Obtain and flash updated BMC firmware from your board OEM.
References
Related entries
- Supermicro X12DPG-QR BIOS 1.4b: Control-flow hijack inside platform firmware, driven by an NVRAM variableCVE-2023-34853 · Supermicro X12DPG-QR BIOS 1.4bHigh
- Dell SmartFabric Storage Software (restricted shell in SSH): OS command injection escaping the restricted shell of theCVE-2023-43068 · Dell SmartFabric Storage Software (restricted shell in SSH)High
- GRUB2 (NTFS filesystem parser): Out-of-bounds write parsing a crafted NTFS volumeCVE-2023-4692 · GRUB2 (NTFS filesystem parser)High
- Phoenix SecureCore Technology 4 (boot splash screen image parsing): The firmware parses a user-supplied boot logo imageCVE-2023-5058 · Phoenix SecureCore Technology 4 (boot splash screen image parsing)High
- Linux kernel (drivers/infiniband/hw/hfi1): User SDMA requests with multiple payload buffers are read past the declaredCVE-2023-52474 · Linux kernel (drivers/infiniband/hw/hfi1)High
- Linux kernel (drivers/infiniband/ulp/ipoib): A PKEY child interface created over netlink comes up with multiple TX/RXCVE-2023-52745 · Linux kernel (drivers/infiniband/ulp/ipoib)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.