Database/Firmware, BMC & network fabric

EDK II NetworkPkg (IScsiDxe, iSCSI login response processing): A hostile iSCSI target answers the firmware initiator
Impact
A hostile iSCSI target answers the firmware initiator with a malformed login response and gets out-of-bounds reads and writes in the pre-OS network stack. Realistic outcome per the upstream advisory is a hung or crashed boot rather than clean code execution, but for a fleet that boots from SAN this is an attacker holding nodes down from the storage side, and the write primitive is a corruption bug that has not been proven unexploitable so much as judged unlikely.
Who can reach it
Whoever controls or can impersonate the iSCSI target the node boots from - a compromised storage appliance, an attacker on the storage VLAN, or a rogue target answering discovery. Unauthenticated from the firmware's point of view, pre-OS.
What to do
OEM BIOS update; flash + reboot per node. Effective config workaround exists and is cheap: disable the UEFI iSCSI initiator on nodes that do not boot from SAN (a BIOS setting, no flash), and where you do boot from iSCSI, enable mutual CHAP so a rogue target cannot complete the login, and keep the storage network on its own VLAN.
References
Related entries
- Lenovo XClarity Administrator (LXCA, insufficient authorization): An authenticated LXCA user without sufficientCVE-2024-45104 · Lenovo XClarity Administrator (LXCA, insufficient authorization)Medium
- Keylime verifier: hardcoded TPM quote nonce lets a compromised node replay stockpiled attestationsCVE-2026-6420 · Keylime verifier (TPM quote nonce, push attestation model)Medium
- Arista EOS: ingress ACLs on shared SVIs stop enforcing after a secondary switch card eventCVE-2026-73451 · Arista EOS ingress security ACLs on shared-mode SVIs (dual switch card systems)Medium
- Linux KVM - PV TLB shootdown leaks memory between guest processes: In a KVM guest with paravirtualised TLB enabled, oneCVE-2019-3016 · Linux KVM - PV TLB shootdown leaks memory between guest processesMedium
- APC Network Management Card 2 (AP9630/AP9631/AP9635) in Smart-UPS, Symmetra and Galaxy 3500: Stored/reflectedCVE-2021-22810 · APC Network Management Card 2 (AP9630/AP9631/AP9635) in Smart-UPS, Symmetra and Galaxy 3500Medium
- Arista EOS (TerminAttr / OpenConfig telemetry transport): The streaming-telemetry agent can leak MACsec keys over theCVE-2021-28509 · Arista EOS (TerminAttr / OpenConfig telemetry transport)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.