Database/Firmware, BMC & network fabric

AMI MegaRAC SPx (BMC hard-coded credentials): Hard-coded credentials inside the BMC firmware
Impact
Hard-coded credentials inside the BMC firmware. Once extracted from a publicly downloadable image, they work on every BMC running that build regardless of what passwords the operator set, so your entire fleet shares an authentication backdoor you cannot rotate. That converts a per-node authentication story into a single fleet-wide key, and BMC access means power control, console, virtual media and firmware.
Who can reach it
Adjacent network reachability to the BMC plus a valid user session and some interaction, per AMI's vector. The credential itself is obtained offline by unpacking a firmware image - no access to your systems is needed for that half.
What to do
Firmware flash to SPx_12.2 / SPx_13.0 or later. This one has been fixed since early SPx builds, so the operator task is an audit: enumerate the actual running BMC firmware version across the fleet and find the SKUs still on a pre-fix ODM image - typically older or white-box nodes whose vendor stopped publishing BMC updates. There is no config-only fix, because the credential is baked into the image; the only compensating control is hard network isolation of the BMC plane so the credential has nothing to authenticate against.
References
Related entries
- Cisco FXOS / NX-OS (LLDP frame handling denial of service): An unauthenticated adjacent attacker sends crafted LLDPCVE-2024-20294 · Cisco FXOS / NX-OS (LLDP frame handling denial of service)Medium
- AMD Zynq UltraScale+ - CSU runtime service address validation in PMU firmware: The PMU firmware on Zynq UltraScale+CVE-2025-0038 · AMD Zynq UltraScale+ - CSU runtime service address validation in PMU firmwareMedium
- TCG TPM 2.0 reference implementation (CryptHmacSign): Out-of-bounds read in the reference implementation's HMAC signingCVE-2025-2884 · TCG TPM 2.0 reference implementation (CryptHmacSign)Medium
- Linux kernel (drivers/infiniband/hw/irdma): A stale flag caused the CQ memory-registration path to read one elementCVE-2026-74346 · Linux kernel (drivers/infiniband/hw/irdma)Medium
- Linux kernel InfiniBand connection manager drivers/infiniband/core/cma.c and cm.c - cm_work_handler race: A race in theCVE-2011-0695 · Linux kernel InfiniBand connection manager drivers/infiniband/core/cma.c and cm.c - cm_work_handler raceMedium
- ibacm 1.0.7 (InfiniBand Communication Manager Assistant daemon) - world-writable log and ibacm.port files: The RDMACVE-2012-4518 · ibacm 1.0.7 (InfiniBand Communication Manager Assistant daemon) - world-writable log and ibacm.port filesMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.