Database/Firmware, BMC & network fabric

AMI MegaRAC SPx 12 / SPx 13 (BMC network service): Heap corruption in the BMC reachable without credentials
Impact
Heap corruption in the BMC reachable without credentials. A reliable exploit gives BMC code execution and therefore persistent, below-the-OS control of the node; a sloppy one just crashes the BMC, which on a GPU node means losing remote power control and console right when you need it - the node keeps running the training job but becomes un-manageable until someone walks the row.
Who can reach it
Adjacent network, unauthenticated, but high attack complexity - the attacker needs heap grooming or a race to win, so this is a targeted-effort bug rather than a spray. Precondition is still just L2 reachability to the BMC NIC.
What to do
Firmware flash to SPx_12.7 / SPx_13.6, out-of-band and per node, subject to ODM rebase. Same rollout cost as the rest of the AMI-SA-2023010 batch, so treat all eight CVEs in that advisory as one flash campaign rather than eight tickets. Interim control is network segmentation of the BMC plane.
References
Related entries
- AMI MegaRAC SPx 12 / SPx 13 (BMC network service): Stack memory corruption in the same unauthenticated BMC parsingCVE-2023-37296 · AMI MegaRAC SPx 12 / SPx 13 (BMC network service)High
- AMI MegaRAC SPx 12 / SPx 13 (BMC network service): The twin of CVE-2023-37293: a stack smash in the BMC'sCVE-2023-3043 · AMI MegaRAC SPx 12 / SPx 13 (BMC network service)Critical
- AMI MegaRAC SPx 12 / SPx 13 (BMC network service): Unauthenticated code execution inside the BMC, reachedCVE-2023-37293 · AMI MegaRAC SPx 12 / SPx 13 (BMC network service)Critical
- AMI MegaRAC SPx (BMC heap memory corruption): Further unauthenticated heap corruption in the MegaRAC BMC reachableCVE-2023-37295 · AMI MegaRAC SPx (BMC heap memory corruption)High
- AMI MegaRAC SPx (BMC heap memory corruption): Heap corruption in the BMC reachable from an adjacent networkCVE-2023-37297 · AMI MegaRAC SPx (BMC heap memory corruption)High
- ArubaOS-Switch web management interface: Unauthenticated stored cross-site scripting against the ArubaOS-Switch web UICVE-2023-39266 · ArubaOS-Switch web management interfaceHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.