Database/Firmware, BMC & network fabric

AMI MegaRAC SPx (BMC cryptography / HMAC): A step is missing when the BMC generates its HMAC, so the authentication tag
Impact
A step is missing when the BMC generates its HMAC, so the authentication tag it produces is weaker than intended and can be forged. The result is that an attacker can present traffic the BMC accepts as authentic - loss of authentication as well as confidentiality and integrity. Practically it degrades whatever assurance you thought you had that a management command came from your orchestration system rather than from something else on the wire.
Who can reach it
Adjacent network, requires an existing high-privilege position and user interaction, at high attack complexity. This is a chaining bug rather than a standalone break-in - it matters mostly as the thing that lets an attacker who already has partial management-plane access forge their way further.
What to do
Firmware flash to SPx_12.2 / SPx_13.0 or later; fixed in early SPx branches, so the real work is verifying that the ODM build actually running on each node is from a fixed branch rather than trusting AMI's fix version. No config-only remediation. Compensate by treating the management network as untrusted transit: bastion-only access, mutual TLS with your own CA, and alerting on BMC sessions that do not originate from your management hosts.
References
Related entries
- AMI MegaRAC SPx (BMC cryptography / HMAC): The BMC uses inadequate HMAC strength, so an attacker positionedCVE-2023-34337 · AMI MegaRAC SPx (BMC cryptography / HMAC)High
- AMD Video Decoder Engine Firmware (VCN FW) - debug code left active: Debug code was shipped active in AMD's Video CoreCVE-2024-36319 · AMD Video Decoder Engine Firmware (VCN FW) - debug code left activeMedium
- EDK II NetworkPkg (IScsiDxe, iSCSI login response processing): A hostile iSCSI target answers the firmware initiatorCVE-2024-38805 · EDK II NetworkPkg (IScsiDxe, iSCSI login response processing)Medium
- Lenovo XClarity Administrator (LXCA, insufficient authorization): An authenticated LXCA user without sufficientCVE-2024-45104 · Lenovo XClarity Administrator (LXCA, insufficient authorization)Medium
- Keylime verifier: hardcoded TPM quote nonce lets a compromised node replay stockpiled attestationsCVE-2026-6420 · Keylime verifier (TPM quote nonce, push attestation model)Medium
- Arista EOS: ingress ACLs on shared SVIs stop enforcing after a secondary switch card eventCVE-2026-73451 · Arista EOS ingress security ACLs on shared-mode SVIs (dual switch card systems)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.