Database/Firmware, BMC & network fabric
Supermicro BMC (IPMI web interface): Part of the same 2023 Supermicro BMC web-interface batch
UnscoredCVE-2023-40286Firmware, BMC & network fabriccurated
Impact
Part of the same 2023 Supermicro BMC web-interface batch - an injection flaw in the management UI that feeds the session-hijack-to-firmware-flash chain.
Who can reach it
Network reach to the BMC web interface; operator interaction for the injection to land.
What to do
BMC firmware flash per board, bundled with the rest of the batch. Score not independently confirmed - treat it as equivalent to its siblings for prioritisation.
References
Related entries
- Linux x86/srso - SRSO mitigation missing for Hygon processors: The kernel's Speculative Return Stack OverflowCVE-2023-52482 · Linux x86/srso - SRSO mitigation missing for Hygon processorsUnscored
- Linux KVM/SVM - source vCPU selection in SEV-ES intra-host migration: KVM fetched source vCPUs from the wrong VMCVE-2023-54296 · Linux KVM/SVM - source vCPU selection in SEV-ES intra-host migrationUnscored
- tpm2-tools (tpm2_checkquote TPM2_GENERATED magic validation): tpm2_checkquote does not verify that the structureCVE-2024-29038 · tpm2-tools (tpm2_checkquote TPM2_GENERATED magic validation)Unscored
- tpm2-tools (tpm2_checkquote PCR selection handling): tpm2_checkquote does not validate the TPML_PCR_SELECTIONCVE-2024-29039 · tpm2-tools (tpm2_checkquote PCR selection handling)Unscored
- Linux kernel mlxbf_gige (BlueField out-of-band management NIC): NULL function-pointer dereference when the DPU'sCVE-2024-35907 · Linux kernel mlxbf_gige (BlueField out-of-band management NIC)Unscored
- Linux kernel mlx5_core eswitch ingress ACL: The eswitch ingress ACL - the table that enforces per-VF ingress policyCVE-2024-42142 · Linux kernel mlx5_core eswitch ingress ACLUnscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.