Database/Firmware, BMC & network fabric

AMI MegaRAC SPx 12 / SPx 13 (BMC network service): Stack memory corruption in the same unauthenticated BMC parsing
Impact
Stack memory corruption in the same unauthenticated BMC parsing surface. Best case for the attacker is BMC code execution and a firmware-level foothold on the node; worst case for the operator without an exploit is a BMC that wedges and needs a physical AC cycle to recover, which on a dense GPU rack means a hands-on trip and possibly draining neighbouring nodes.
Who can reach it
Adjacent network, no credentials, high complexity. Anything on the management VLAN - including a compromised BMC on a neighbouring node - is close enough.
What to do
Firmware flash to SPx_12.7 / SPx_13.6. Out-of-band, per node, ODM-gated. No config-only fix inside the BMC; the compensating control is to make the management VLAN unreachable from tenant and general corporate networks and to keep the BMC off any routable address space.
References
Related entries
- AMI MegaRAC SPx 12 / SPx 13 (BMC network service): The twin of CVE-2023-37293: a stack smash in the BMC'sCVE-2023-3043 · AMI MegaRAC SPx 12 / SPx 13 (BMC network service)Critical
- AMI MegaRAC SPx 12 / SPx 13 (BMC network service): Unauthenticated code execution inside the BMC, reachedCVE-2023-37293 · AMI MegaRAC SPx 12 / SPx 13 (BMC network service)Critical
- AMI MegaRAC SPx 12 / SPx 13 (BMC network service): Heap corruption in the BMC reachable without credentialsCVE-2023-37294 · AMI MegaRAC SPx 12 / SPx 13 (BMC network service)High
- AMI MegaRAC SPx (BMC heap memory corruption): Heap corruption in the BMC reachable from an adjacent networkCVE-2023-37297 · AMI MegaRAC SPx (BMC heap memory corruption)High
- ArubaOS-Switch web management interface: Unauthenticated stored cross-site scripting against the ArubaOS-Switch web UICVE-2023-39266 · ArubaOS-Switch web management interfaceHigh
- Supermicro BMC (IPMI web interface, XSS): Stored/reflected script injection in the BMC web UICVE-2023-40284 · Supermicro BMC (IPMI web interface, XSS)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.