Database/Firmware, BMC & network fabric

AMI MegaRAC SPx (BMC web interface, HTTP header handling): CRLF sequences are not neutralised in HTTP headers, so
Impact
CRLF sequences are not neutralised in HTTP headers, so an attacker can split responses and inject headers of their choosing. Against a BMC web UI the payoff is session and cache manipulation against an administrator's browser - poisoning what the admin sees, planting cookies, or setting up a follow-on credential capture. It is an integrity bug that is useful as a stepping stone toward hijacking an admin's BMC session rather than a direct takeover.
Who can reach it
Adjacent network with a low-privilege BMC account. Requires an administrator to subsequently interact with the BMC web interface for the payoff, so it depends on your ops team actually using the web UI - which most do for KVM and console access.
What to do
Firmware flash to SPx_12.5 / SPx_13.3 or later, out-of-band per node, ODM-gated. Low priority relative to the rest of this cluster, so fold it into the same flash campaign rather than scheduling separately. Config-only reduction: reach BMC web UIs only from a hardened jump host with a dedicated browser profile, so an admin session cannot be crossed with anything else.
References
Related entries
- AMD Secure Processor - cryptographic key usage control: Once an attacker has arbitrary code execution inside the ASPCVE-2024-21981 · AMD Secure Processor - cryptographic key usage controlMedium
- Intel TDX: insufficient verification of data authenticity in the ring 0 interface leaks trust-domain dataCVE-2025-31356 · Intel TDX (hypervisor-facing ring 0 interface)Medium
- Caliptra Core ROM: TOCTOU in update-reset lets compromised MCU firmware bypass secure boot silentlyCVE-2026-11835 · Caliptra Core ROM (UpdateResetFlow staging-address validation)Medium
- Intel processors (indirect branch prediction): Spectre v2: an attacker trains the indirect branch predictor so that aCVE-2017-5715 · Intel processors (indirect branch prediction)Medium
- Intel processors (bounds check bypass): Spectre v1: speculative execution past a bounds check lets an attacker readCVE-2017-5753 · Intel processors (bounds check bypass)Medium
- Intel processors (rogue data cache load): Meltdown: unprivileged code reads kernel memory - and on affected partsCVE-2017-5754 · Intel processors (rogue data cache load)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.