Database/Firmware, BMC & network fabric

AMI MegaRAC SPx (SPX REST API): Shell command injection through the BMC's REST API
Impact
Shell command injection through the BMC's REST API. An administrative BMC user gets a root shell on the management controller's Linux - which is a large step up from what the web UI lets them do, because from a BMC shell the attacker can write firmware, install a persistent implant in the BMC's own flash, and pivot to the host. The gap between 'has a BMC admin password' and 'owns the node forever' closes here.
Who can reach it
Network-reachable REST API with an administrative BMC account. Same shared-credential exposure as the rest of the SPX REST API family: assume any leaked BMC admin password is a fleet-wide credential unless you have proven otherwise.
What to do
Firmware flash to SPx_12.7 / SPx_13.5, out-of-band per node, ODM-gated. Config-only compensations that actually reduce blast radius: unique BMC credentials per node, an allowlist ACL restricting who can reach the BMC web/REST port at all, and logging of BMC authentication to your SIEM so a credential-spray across the management VLAN is visible.
References
Related entries
- AMI MegaRAC SPx (SPX REST API): Path traversal in the BMC REST API letting a low-privilege user read arbitrary filesCVE-2023-34345 · AMI MegaRAC SPx (SPX REST API)Medium
- AMI MegaRAC SPx (SPX REST API): Arbitrary read and write into the memory of the BMC's IPMI server process via the SPXCVE-2023-34341 · AMI MegaRAC SPx (SPX REST API)High
- Supermicro BMC (IPMI web interface, command injection): Command injection that turns a BMC administrator accountCVE-2023-40289 · Supermicro BMC (IPMI web interface, command injection)High
- Dell PowerEdge Server BIOS (SMM communication buffer): The BIOS fails to properly validate the SMM communicationCVE-2024-0161 · Dell PowerEdge Server BIOS (SMM communication buffer)High
- Supermicro BMC firmware validation (MBD-X12DPG-OA6): Root-of-Trust bypassCVE-2024-10237 · Supermicro BMC firmware validation (MBD-X12DPG-OA6)High
- Supermicro BMC firmware image verification routine on MBD-X12DPG-OA6: A crafted update image smashes the stackCVE-2024-10238 · Supermicro BMC firmware image verification routine on MBD-X12DPG-OA6High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.