Database/Firmware, BMC & network fabric
Supermicro BMC (IPMI web interface, command injection): Command injection that turns a BMC administrator account
Impact
Command injection that turns a BMC administrator account into shell on the BMC's own Linux. That matters more than it sounds: BMC admin is a constrained management role, whereas BMC shell means arbitrary firmware modification, access to the host over the internal bridges, and a place to hide that no host-side agent can inspect. Chained after any of the XSS bugs in the same batch, an operator merely visiting a page is enough to reach it.
Who can reach it
An authenticated BMC administrator - or, realistically, an attacker who chained an XSS in the same firmware to ride an admin's session. Requires network reach to the BMC web interface.
What to do
BMC firmware flash per board, out-of-band. Supermicro fixes ship per-SKU and lag disclosure, so expect a long tail of boards with no image. Interim controls that work today: keep the BMC web UI off any routable network, require a jump host, and stop using shared BMC admin credentials across the fleet so one compromise is not fleet-wide.
References
Related entries
- Dell PowerEdge Server BIOS (SMM communication buffer): The BIOS fails to properly validate the SMM communicationCVE-2024-0161 · Dell PowerEdge Server BIOS (SMM communication buffer)High
- Supermicro BMC firmware validation (MBD-X12DPG-OA6): Root-of-Trust bypassCVE-2024-10237 · Supermicro BMC firmware validation (MBD-X12DPG-OA6)High
- Supermicro BMC firmware image verification routine on MBD-X12DPG-OA6: A crafted update image smashes the stackCVE-2024-10238 · Supermicro BMC firmware image verification routine on MBD-X12DPG-OA6High
- Supermicro OpenBMC firmware image verification (MBD-X12DPG-OA6), fat->fsd.max_fld field: The BMC's own firmware-imageCVE-2024-10239 · Supermicro OpenBMC firmware image verification (MBD-X12DPG-OA6), fat->fsd.max_fld fieldHigh
- Intel Xeon memory controller configuration (with SGX): Incorrect default permissions on Xeon memory controllerCVE-2024-21820 · Intel Xeon memory controller configuration (with SGX)High
- Intel Server D50DNP UEFI firmware (PlatformVariableInitDxe): Improper input validation in a UEFI DXE driver on IntelCVE-2024-22095 · Intel Server D50DNP UEFI firmware (PlatformVariableInitDxe)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.