Database/Firmware, BMC & network fabric

AMI MegaRAC SPx (Redfish Host Interface): Unauthenticated auth bypass, full BMC takeover, malicious firmware flash.
Impact
Unauthenticated auth bypass, full BMC takeover, malicious firmware flash. Persists below the OS and survives reimaging
Who can reach it
Network / Redfish host interface, unauthenticated
What to do
Out-of-band BMC flash on every node; requires an ODM rebase of the AMI fix (Supermicro / Lenovo / HPE / ASRock each ship their own build, availability lags AMI by months), bricking risk on interrupted flash
Fleet impact
How widespread
universal - AMI MegaRAC is the OEM BMC stack shipped under most Supermicro/ASRock Rack/Gigabyte/Quanta GPU servers
Cost to remediate
firmware-flash - BMC firmware image per node, applied out-of-band, and the OEM must first rebase AMI's fix into its own build; realistically a rolling node-drain because a bad flash bricks the board
Why it hits the whole fleet
Unauthenticated Redfish auth bypass by spoofing the X-Server-Addr/Host header gives full BMC takeover on every node running the same OEM image; the BMC sits below the hypervisor, so an implant survives OS reimaging and GPU node rebuilds. First BMC CVE ever added to CISA KEV (2025-06-25).
References
Related entries
- Linux bnxt_en driver (5760X / P7 aggregation ID mask): The bnxt_en driver mishandles the aggregation ID mask on 5760XCVE-2024-56656 · Linux bnxt_en driver (5760X / P7 aggregation ID mask)Critical
- Linux kernel (drivers/infiniband/hw/bnxt_re): The driver advertises support for 13 scatter-gather entries per workCVE-2024-57936 · Linux kernel (drivers/infiniband/hw/bnxt_re)Critical
- Linux kernel (drivers/infiniband/ulp/rtrs): A remote client corrupts kernel linked lists on the RDMA block-storageCVE-2025-21805 · Linux kernel (drivers/infiniband/ulp/rtrs)Critical
- Linux kernel (drivers/infiniband/hw/erdma): Use-after-free while accepting an inbound RDMA connection. The connectionCVE-2025-22088 · Linux kernel (drivers/infiniband/hw/erdma)Critical
- Linux kernel (drivers/infiniband/core): The iWARP connection manager frees the work objects it is currently executingCVE-2025-38211 · Linux kernel (drivers/infiniband/core)Critical
- Linux bnxt_en driver (XDP redirect list flush): List corruption in the XDP redirect path, found crashing productionCVE-2025-38246 · Linux bnxt_en driver (XDP redirect list flush)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.