Database/Firmware, BMC & network fabric

AMI MegaRAC SPx (IPMI handler): Timing and response differences in the IPMI handler let an unauthenticated attacker
Impact
Timing and response differences in the IPMI handler let an unauthenticated attacker confirm which usernames exist on the BMC. On its own it leaks nothing but names; in a fleet it is the reconnaissance step that makes credential-stuffing efficient, because it tells the attacker which nodes still carry the vendor default account or the provisioning template's service account before they spend any attempts.
Who can reach it
Network-reachable IPMI service, no credentials, no interaction. Any host that can reach UDP/623 on the BMC can enumerate accounts across the whole management range in a single sweep.
What to do
Firmware flash to SPx_12.7 / SPx_13.5, out-of-band per node, ODM-gated. Genuinely low urgency for the flash itself. The config-only work is what matters: remove or rename vendor default accounts, ensure no username is shared across the fleet by the provisioning template, and disable IPMI-over-LAN where your tooling allows it - that closes the enumeration surface outright with no reboot.
References
Related entries
- AMI MegaRAC SPx (IPMI handler): Buffer overflow in the BMC's IPMI message handler leading to code executionCVE-2023-34336 · AMI MegaRAC SPx (IPMI handler)High
- AMI MegaRAC SPx (IPMI handler): Arbitrary file upload and download through the BMC's IPMI handlerCVE-2023-34342 · AMI MegaRAC SPx (IPMI handler)Medium
- Juniper Junos OS J-Web (EX): PHP external variable modificationCVE-2023-36844 · Juniper Junos OS J-Web (EX)Medium
- Juniper Junos OS J-Web (EX): Missing authentication on `installAppPackage.php` — unauthenticated file upload to theCVE-2023-36847 · Juniper Junos OS J-Web (EX)Medium
- Linux KVM - SEV-ES/SEV-SNP VMGEXIT double-fetch race: A KVM guest running SEV-ES or SEV-SNP with several vCPUs canCVE-2023-4155 · Linux KVM - SEV-ES/SEV-SNP VMGEXIT double-fetch raceMedium
- GRUB2 (NTFS filesystem parser): Out-of-bounds read in the same NTFS path leaks GRUB heap memoryCVE-2023-4693 · GRUB2 (NTFS filesystem parser)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.