Database/Firmware, BMC & network fabric

Microchip maxView Storage Manager Redfish server (Adaptec SmartRAID / SmartHBA controllers), 3.00.23484 through
Impact
In a default install where the Redfish server is enabled for remote management, the Redfish endpoint accepts unauthorized requests - read and write. The attacker gets the controller's own management API for Adaptec SmartRAID/SmartHBA: enumerate logical drives, change configuration, and reach controller update functions. Wiping or reconfiguring an array under a live training job is a fleet-availability event; the controller-update path is the worse one, because Adaptec controller firmware runs below the host OS with DMA and survives a tenant reimage, so an operator cannot honestly certify tenant handoff on a node that was exposed. CVSS 10.0 with a scope change is the vendor's own rating.
Who can reach it
Any host that can reach the maxView Redfish listener on the management network - no credentials. maxView is commonly installed by OEM server tooling and its Redfish service is on by default, so this is usually reachable from the provisioning VLAN rather than only from a hardened admin subnet.
What to do
Upgrade maxView Storage Manager to 4.14.00.26068 or later (Microchip also back-patched 3.07.23980 and 4.07.00.25339). Software-only - restart the maxView service, no controller flash, no arrays offline. If you do not actually consume the Redfish interface, disable the maxView Redfish server outright; that is the faster fleet-wide mitigation and costs nothing. Note the OEM lag explicitly: Siemens shipped the same defect as CVE-2023-51438 in its industrial PCs a year later, and Dell/HPE/Supermicro rebadge maxView the same way - check the OEM bundle version, not just Microchip's.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.