Database/Firmware, BMC & network fabric

IBM Server Firmware: unauthenticated request crashes the ASMI management web server
Impact
An unauthenticated attacker on the management network sends a malformed HTTPS request and crashes the ASMI web server, with possible memory corruption. ASMI restarts itself, but repeated requests keep it down, which means losing the out-of-band path used to power-cycle, inspect, or recover the server - exactly what an operator needs when a node is already unhealthy. On a fleet where the management network is shared across racks, one attacker with management-VLAN access can hold ASMI down across many servers at once. IBM rates the impact as integrity and availability; the record does not claim code execution, and 'possible memory corruption' is as far as the advisory goes.
Who can reach it
Anyone able to reach ASMI over HTTPS on the management network. No authentication required. Adjacent-network only per the CVSS vector - not exploitable from outside unless the management network is exposed.
What to do
Apply IBM Server Firmware updates above the affected levels (FW1120.00-FW1120.01, FW1110.00-FW1110.31, FW1060.00-FW1060.81, FW950.00-FW950.H3); see the IBM support bulletin for the fix level per release stream. This is a service processor firmware update - concurrent on some levels, otherwise requiring the system out of service, so plan per IBM's guidance for the target level. Until then, keep ASMI reachable only from a restricted management segment or jump host.
References
Related entries
- HPE iLO 4 / iLO 5 (remote buffer overflow): Remotely triggerable buffer overflow in the iLO firmware on both the Gen9CVE-2019-11983 · HPE iLO 4 / iLO 5 (remote buffer overflow)High
- Insyde InsydeH2O (PnpSmm shared SMM/non-SMM buffer, DMA TOCTOU): A buffer shared between SMM and non-SMM codeCVE-2022-32469 · Insyde InsydeH2O (PnpSmm shared SMM/non-SMM buffer, DMA TOCTOU)High
- Insyde InsydeH2O (FwBlockServiceSmm shared buffer, DMA TOCTOU): The firmware block service's shared buffer is racy, soCVE-2022-32470 · Insyde InsydeH2O (FwBlockServiceSmm shared buffer, DMA TOCTOU)High
- Insyde InsydeH2O (IhisiSmm / IhisiDxe command buffer): One representative of a family of roughly a dozen InsydeCVE-2022-32471 · Insyde InsydeH2O (IhisiSmm / IhisiDxe command buffer)High
- Insyde InsydeH2O (HddPassword shared buffer, DMA TOCTOU): Racy shared buffer in the ATA security driverCVE-2022-32473 · Insyde InsydeH2O (HddPassword shared buffer, DMA TOCTOU)High
- Insyde InsydeH2O (StorageSecurityCommandDxe shared buffer, DMA TOCTOU): The TCG/Opal security-command driver sharesCVE-2022-32474 · Insyde InsydeH2O (StorageSecurityCommandDxe shared buffer, DMA TOCTOU)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.