Database/Firmware, BMC & network fabric

AMI MegaRAC SPx (BMC heap memory corruption): Heap corruption in the BMC reachable from an adjacent network
CVSS 8.3CVE-2023-37297Firmware, BMC & network fabriccurated
Impact
Heap corruption in the BMC reachable from an adjacent network without authentication, with scope change.
Who can reach it
Adjacent-network access to the BMC.
What to do
Obtain and flash updated BMC firmware from your board OEM.
References
Related entries
- AMI MegaRAC SPx (BMC heap memory corruption): Further unauthenticated heap corruption in the MegaRAC BMC reachableCVE-2023-37295 · AMI MegaRAC SPx (BMC heap memory corruption)High
- ArubaOS-Switch web management interface: Unauthenticated stored cross-site scripting against the ArubaOS-Switch web UICVE-2023-39266 · ArubaOS-Switch web management interfaceHigh
- Supermicro BMC (IPMI web interface, XSS): Stored/reflected script injection in the BMC web UICVE-2023-40284 · Supermicro BMC (IPMI web interface, XSS)High
- Supermicro BMC (IPMI web interface, XSS): Script injection in the BMC management UI, scope-changing becauseCVE-2023-40287 · Supermicro BMC (IPMI web interface, XSS)High
- Supermicro BMC (IPMI web interface, XSS): Further injection point in the same BMC web stackCVE-2023-40288 · Supermicro BMC (IPMI web interface, XSS)High
- Supermicro BMC (IPMI web interface, XSS via IE11): Injection that fires specifically through Internet Explorer 11CVE-2023-40290 · Supermicro BMC (IPMI web interface, XSS via IE11)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.