Database/Firmware, BMC & network fabric
shim (HTTP boot): Out-of-bounds write from a crafted HTTP response during network boot
CVSS 8.3CVE-2023-40547Firmware, BMC & network fabriccurated
Impact
Out-of-bounds write from a crafted HTTP response during network boot — full system compromise at the pre-boot stage, before any OS security control exists
Who can reach it
Adjacent network, MITM on the boot server or a compromised PXE/HTTP boot server
What to do
New signed shim rollout plus dbx revocation of the old one. Directly relevant to neoclouds because netboot provisioning is the standard bare-metal reimaging path — the provisioning network is the attack surface
References
Related entries
- AMI AptioV UEFI BIOS (EDK II network stack, DHCPv6 client): Buffer overflow in the firmware's DHCPv6 client, triggeredCVE-2023-45230 · AMI AptioV UEFI BIOS (EDK II network stack, DHCPv6 client)High
- IBM Power Systems Firmware: ASMI web interface performs admin actions from a page a logged-in admin visitsCVE-2026-18848 · IBM Power Systems Firmware (ASMI web interface)High
- Eaton Tripp Lite series PADM firmware, session management interface: An authenticated administrator can break outCVE-2026-22621 · Eaton Tripp Lite series PADM firmware, session management interfaceHigh
- IBM BladeCenter AMM (before 3.66E), IMM (before 1.43), IMM2: The in-band host-to-BMC pivot, with a CVE attached. TheCVE-2014-0860 · IBM BladeCenter AMM (before 3.66E), IMM (before 1.43), IMM2High
- Power Management Controller (PMC) firmware in systems using Intel CSME 11.x/12.0 or Intel SPS 4.x: An administrativeCVE-2018-3643 · Power Management Controller (PMC) firmware in systems using Intel CSME 11.x/12.0 or Intel SPS 4.xHigh
- BMC firmware on Intel server boards, compute modules and systems - SMBus access control: An attackerCVE-2018-3682 · BMC firmware on Intel server boards, compute modules and systems - SMBus access controlHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.