GPU VulnDB

Database/Firmware, BMC & network fabric

AMI MegaRAC SPx 12 / SPx 13 (BMC network service): Heap corruption in the BMC reachable without credentials

CVE-2023-37294Firmware, BMC & network fabricAMI-SA-2023010curated

Impact

Heap corruption in the BMC reachable without credentials. A reliable exploit gives BMC code execution and therefore persistent, below-the-OS control of the node; a sloppy one just crashes the BMC, which on a GPU node means losing remote power control and console right when you need it - the node keeps running the training job but becomes un-manageable until someone walks the row.

Who can reach it

Adjacent network, unauthenticated, but high attack complexity - the attacker needs heap grooming or a race to win, so this is a targeted-effort bug rather than a spray. Precondition is still just L2 reachability to the BMC NIC.

What to do

Firmware flash to SPx_12.7 / SPx_13.6, out-of-band and per node, subject to ODM rebase. Same rollout cost as the rest of the AMI-SA-2023010 batch, so treat all eight CVEs in that advisory as one flash campaign rather than eight tickets. Interim control is network segmentation of the BMC plane.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.