Database/Firmware, BMC & network fabric

AMI MegaRAC SPx (BMC TLS certificate / cryptographic keys): A hard-coded certificate and its private key ship inside
Impact
A hard-coded certificate and its private key ship inside the firmware, so the same key is on every BMC built from that image across every customer of that ODM. Anyone who extracts it once - and firmware images are downloadable from vendor support sites - can impersonate any BMC's HTTPS endpoint or decrypt intercepted management traffic. The operator consequence is that TLS on your management plane is decorative: admin passwords, Redfish tokens and KVM sessions are recoverable by an attacker who can interpose.
Who can reach it
Adjacent network with the ability to interpose on BMC traffic and some operator interaction (an admin logging into the BMC). No credentials needed - the attacker supplies the trust. A compromised management jump host, a rogue device on the management VLAN, or an ARP/DHCP position on that segment is enough.
What to do
Firmware flash to SPx_12.3 / SPx_13.0 or later, but the flash is only half the fix - a fixed image does not retroactively replace a certificate already in place. After flashing you must generate and install a unique per-node BMC certificate signed by your own internal CA, which is a config operation over Redfish and can be automated, no reboot required. Do the certificate rotation even on nodes you cannot yet flash; it is the part that actually removes the shared key.
References
Related entries
- Intel TDX module: Insufficient control-flow management in the TDX module lets a privileged host user deny serviceCVE-2024-21801 · Intel TDX moduleHigh
- SEV-ES / SEV-SNP guest kernel - injection of virtual interrupts 0 and 14: An untrusted hypervisor can inject virtualCVE-2024-25743 · SEV-ES / SEV-SNP guest kernel - injection of virtual interrupts 0 and 14High
- Arista EOS and CVX: malformed CVX cluster messages crash the Sysdb agent and soft-reset the switchCVE-2025-5089 · Arista EOS / CloudVision eXchange (CVX) - Sysdb agent message handlingHigh
- Arista CVX: unexpected messages from a connected switch crash CVX agents and destabilise the clusterCVE-2025-5090 · Arista CloudVision eXchange (CVX) server - switch message handlingHigh
- Arista EOS: crafted DHCP packet restarts the DHCP relay service on client-facing VLANsCVE-2026-19655 · Arista EOS DHCP relay (Option 82 information option handling)High
- Cisco UCS UEFI Shell: memory write commands bypass Secure Boot validationCVE-2026-20293 · Cisco UCS server BIOS (UEFI Shell)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.