Database/Firmware, BMC & network fabric

IBM OpenBMC bmcweb HTTPS server (FW1050.00 - FW1050.10): Certain URIs on IBM's OpenBMC-derived bmcweb return
Impact
Certain URIs on IBM's OpenBMC-derived bmcweb return their content to callers who never authenticated. The Redfish tree is where BMC-side inventory lives - serial numbers, firmware versions, sensor and account metadata - so an unauthenticated reader on the management VLAN gets a precise map of the fleet: which nodes run which firmware, and therefore which nodes are still vulnerable to everything else in this cluster. It is reconnaissance rather than control, but it is the reconnaissance that makes a targeted BMC campaign cheap.
Who can reach it
Unauthenticated HTTPS to the BMC's Redfish/web endpoint. Any host that can route to the management network.
What to do
Fixed in IBM firmware after FW1050.10; delivery is an OpenPower/Power system firmware update, which on IBM hardware is a supported in-band update path rather than a raw SPI flash, but still a per-node reboot-class operation with a maintenance window. Config-only first move: confirm no BMC in the fleet answers HTTPS from outside your management VLAN, and treat any Redfish data reachable pre-auth as public.
References
Related entries
- IBM OpenBMC default password and session management (FW1020, FW1030, FW1050): The combination of a shipped defaultCVE-2024-35124 · IBM OpenBMC default password and session management (FW1020, FW1030, FW1050)High
- Supermicro BIOS (arbitrary memory write, X11DPH series): Arbitrary memory write from firmware context on X11DPH boardsCVE-2024-36433 · Supermicro BIOS (arbitrary memory write, X11DPH series)High
- Supermicro BIOS SMM callout (X11DPH-T / X11DPH-Tq): Execution in System Management Mode, the most privileged executionCVE-2024-36434 · Supermicro BIOS SMM callout (X11DPH-T / X11DPH-Tq)High
- Dell SmartFabric OS10 (uncontrolled resource consumption): A remote unauthenticated host can exhaust resources on anCVE-2024-37125 · Dell SmartFabric OS10 (uncontrolled resource consumption)High
- Sunbird DCIM dcTrack v9.1.2 - ticket location RBAC: Incorrect access control lets an attacker create or update ticketsCVE-2024-37775 · Sunbird DCIM dcTrack v9.1.2 - ticket location RBACHigh
- Dell SmartFabric OS10 (command injection): Command injection in SmartFabric OS10 10.5.5.4-10.5.5.10 and 10.5.6.xCVE-2024-38486 · Dell SmartFabric OS10 (command injection)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.