Database/Firmware, BMC & network fabric

Microchip maxView Storage Manager Redfish server (Adaptec SmartRAID / SmartHBA controllers), 3.00.23484 through
Impact
In a default install where the Redfish server is enabled for remote management, the Redfish endpoint accepts unauthorized requests - read and write. The attacker gets the controller's own management API for Adaptec SmartRAID/SmartHBA: enumerate logical drives, change configuration, and reach controller update functions. Wiping or reconfiguring an array under a live training job is a fleet-availability event; the controller-update path is the worse one, because Adaptec controller firmware runs below the host OS with DMA and survives a tenant reimage, so an operator cannot honestly certify tenant handoff on a node that was exposed. CVSS 10.0 with a scope change is the vendor's own rating.
Who can reach it
Any host that can reach the maxView Redfish listener on the management network - no credentials. maxView is commonly installed by OEM server tooling and its Redfish service is on by default, so this is usually reachable from the provisioning VLAN rather than only from a hardened admin subnet.
What to do
Upgrade maxView Storage Manager to 4.14.00.26068 or later (Microchip also back-patched 3.07.23980 and 4.07.00.25339). Software-only - restart the maxView service, no controller flash, no arrays offline. If you do not actually consume the Redfish interface, disable the maxView Redfish server outright; that is the faster fleet-wide mitigation and costs nothing. Note the OEM lag explicitly: Siemens shipped the same defect as CVE-2023-51438 in its industrial PCs a year later, and Dell/HPE/Supermicro rebadge maxView the same way - check the OEM bundle version, not just Microchip's.
References
Related entries
- Linux bnxt_en driver (XDP_REDIRECT double DMA unmap): A double DMA unmap in the XDP_REDIRECT pathCVE-2024-44984 · Linux bnxt_en driver (XDP_REDIRECT double DMA unmap)Critical
- Lantronix PremierWave 2050 console server (Web Manager): An attacker who can log into the web management console getsCVE-2021-21872 · Lantronix PremierWave 2050 console server (Web Manager)Critical
- Lantronix PremierWave 2050 console server (Web Manager): Same class of bug as the Traceroute injection on this deviceCVE-2021-21883 · Lantronix PremierWave 2050 console server (Web Manager)Critical
- Linux kernel iWARP driver drivers/infiniband/hw/cxgb3/iwch_cm.c (Chelsio T3): Unauthenticated remote code execution inCVE-2015-8812 · Linux kernel iWARP driver drivers/infiniband/hw/cxgb3/iwch_cm.c (Chelsio T3)Critical
- Cisco NX-OS / FXOS (Cisco Fabric Services): Unauthenticated remote code execution as root through Cisco FabricCVE-2018-0314 · Cisco NX-OS / FXOS (Cisco Fabric Services)Critical
- Eaton Intelligent Power Manager v1.6 - node_upgrade_srv.js firmware parameter: Local file inclusion through directoryCVE-2018-12031 · Eaton Intelligent Power Manager v1.6 - node_upgrade_srv.js firmware parameterCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.