Database/Firmware, BMC & network fabric

Intel Server OpenBMC firmware (before egs-1.15-0 / bhs-0.27): An out-of-bounds read reachable by a privileged BMC user
Impact
An out-of-bounds read reachable by a privileged BMC user leaks memory contents across a scope boundary - CVSS v4 scores it 8.1, notably higher than the v3 6.7, because the disclosure crosses out of the vulnerable component. What comes back is BMC process memory, which on this stack means session tokens, credential material and configuration. Combined with the privilege-escalation entry from the same product line, an attacker with a modest BMC account has a path to reading things that let them keep the access permanently.
Who can reach it
Local access on the BMC with a privileged account. Requires an existing high-privilege BMC credential, so this is a post-compromise deepening tool rather than an entry point.
What to do
Fixed in Intel Server OpenBMC egs-1.15-0 / bhs-0.27 and later - per-node out-of-band BMC firmware update via Intel platform packages, subject to OEM rebase lag on boards that derive from the same base. No config-only mitigation for the bug itself; limit the blast radius by minimizing the number of accounts holding BMC admin and by rotating BMC credentials after any suspected node compromise.
References
Related entries
- Micron Crucial MX500 series SSD, firmware M3CR046CVE-2024-42642 · Micron Crucial MX500 series SSD, firmware M3CR046 - buffer overflow in the drive controller reachable from host ATA…Medium
- Lenovo ThinkSystem UEFI/BIOS (SMM callout): A System Management Mode callout vulnerability in ThinkSystem UEFICVE-2024-45105 · Lenovo ThinkSystem UEFI/BIOS (SMM callout)Medium
- Lenovo ThinkSystem / ThinkStation (firmware buffer overflow): A local attacker with elevated privileges executesCVE-2024-4550 · Lenovo ThinkSystem / ThinkStation (firmware buffer overflow)Medium
- GRUB2 (JPEG parser): Out-of-bounds write in GRUB's JPEG parser from a crafted imageCVE-2024-45774 · GRUB2 (JPEG parser)Medium
- GRUB2 (commands/extcmd): A failed allocation goes unchecked, so GRUB proceeds on a NULL pointer and its stateCVE-2024-45775 · GRUB2 (commands/extcmd)Medium
- GRUB2 (BFS filesystem parser): Integer overflow in the BeFS parser leads to heap corruptionCVE-2024-45778 · GRUB2 (BFS filesystem parser)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.