Database/Firmware, BMC & network fabric

EDK II NetworkPkg (TCP initial sequence number generation): The firmware's TCP initial sequence numbers
Impact
The firmware's TCP initial sequence numbers are predictable, so an off-path attacker can inject into or hijack the boot-time TCP session. In practice that means substituting the payload the node is downloading - the HTTP-boot image, the kernel, the initrd - without ever being on the wire. For a bare-metal GPU cloud that HTTP-boots tenant images, this is a supply-chain swap at provisioning time that no post-boot integrity check will notice if the swapped image is what gets measured.
Who can reach it
Off-path attacker who can guess the ISN - no need to sit on the provisioning segment at all, which makes this materially worse than the on-link PixieFail bugs. Unauthenticated, pre-OS.
What to do
OEM BIOS update; the fix replaces the ISN generator, so there is no configuration toggle that helps. Flash + reboot per node. Compensating control while you wait: use HTTPS boot with proper certificate validation rather than plain HTTP/TFTP, and verify signatures on the downloaded image inside the boot flow rather than relying on transport integrity.
References
Related entries
- EDK II NetworkPkg (PseudoRandom number generation used by the network stack): The weak PRNG behind the previous issueCVE-2023-45237 · EDK II NetworkPkg (PseudoRandom number generation used by the network stack)High
- Lenovo XClarity Controller (XCC) - permission API: An authenticated XCC user can change the permissions of any userCVE-2023-4607 · Lenovo XClarity Controller (XCC) - permission APIHigh
- HPE iLO 5 / iLO 6 (authentication bypass): Authentication bypass on the iLO itself, remotely, with no credentialsCVE-2023-50272 · HPE iLO 5 / iLO 6 (authentication bypass)High
- Linux kernel (drivers/infiniband/sw/siw): When soft-iWARP fails to process an inbound MPA connection requestCVE-2023-52513 · Linux kernel (drivers/infiniband/sw/siw)High
- Phoenix SecureCore (TPM configuration / SetupUtility, unsafe UEFI variable handling in SMM): A buffer overflow in howCVE-2024-0762 · Phoenix SecureCore (TPM configuration / SetupUtility, unsafe UEFI variable handling in SMM)High
- Brocade Fabric OS (firmware download credential capture): Fabric OS captures the SFTP/FTP server password usedCVE-2024-10403 · Brocade Fabric OS (firmware download credential capture)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.