Database/Firmware, BMC & network fabric

AMI MegaRAC SPx (IPMI handler): Arbitrary file upload and download through the BMC's IPMI handler
Impact
Arbitrary file upload and download through the BMC's IPMI handler. Download gives the attacker the BMC's stored secrets and configuration; upload gives them a way to drop a payload onto the controller's filesystem and, depending on where it lands, get it executed - which is how a credentialed foothold becomes a persistent BMC implant. Availability damage is also on the table: writing over the wrong file bricks the controller.
Who can reach it
Local access to the BMC with high privileges per AMI's vector - i.e. an attacker who already holds a BMC admin credential or has landed on the controller. Its role in a real chain is post-exploitation persistence, not initial access.
What to do
Firmware flash to SPx_12.7 / SPx_13.5, out-of-band per node, ODM-gated. Config-only reduction: disable IPMI-over-LAN so the handler is not reachable from the network at all and drive management through Redfish, accepting that this breaks ipmitool-based provisioning and monitoring tooling. Also worth doing regardless: alert on any BMC firmware or filesystem change, because this class of bug is invisible from the host OS.
References
Related entries
- AMI MegaRAC SPx (IPMI handler): Timing and response differences in the IPMI handler let an unauthenticated attackerCVE-2023-34344 · AMI MegaRAC SPx (IPMI handler)Medium
- AMI MegaRAC SPx (IPMI handler): Buffer overflow in the BMC's IPMI message handler leading to code executionCVE-2023-34336 · AMI MegaRAC SPx (IPMI handler)High
- Intel TDX module: The TDX module is the software that stands between the host/VMM and every confidential VM on the boxCVE-2023-47855 · Intel TDX moduleMedium
- Cisco NX-OS CLI: Command injection giving root on the switch's underlying OS from an admin CLI sessionCVE-2024-20399 · Cisco NX-OS CLIMedium
- Intel TDX SEAM loader (Seamldr): Sensitive information is not cleared before a resource is reused in the SEAM loaderCVE-2024-21850 · Intel TDX SEAM loader (Seamldr)Medium
- AMD SEV-SNP firmware - input validation: Improper input validation in SEV-SNP lets a malicious hypervisor read orCVE-2024-21978 · AMD SEV-SNP firmware - input validationMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.