Database/Firmware, BMC & network fabric

ASPEED BMC (host-to-BMC bridges generally): The ASPEED LPC/PCIe bridge architecture exists to let the host talk
UnscoredNCVD-0000-001-aspeed-bmc-host-to-bmc-bridges-gFirmware, BMC & network fabriccurated
Impact
The ASPEED LPC/PCIe bridge architecture exists to let the host talk to the BMC; disabling it breaks legitimate in-band management (ipmitool, firmware update tooling). Operators frequently leave it on
Who can reach it
Local, host CPU
What to do
Explicit per-fleet decision: lock the AHB bridges and lose in-band management tooling, or accept a host→BMC escalation path. There is no configuration that gives both
References
Related entries
- IPMI over LAN as a protocol: IPMI has no transport confidentiality guarantees worth relying on, weak session handlingNCVD-0000-002-ipmi-over-lan-as-a-protocol · IPMI over LAN as a protocolUnscored
- Internet-exposed BMC: Shodan-visible BMCs are a recurring finding at colo/neocloud buildoutsNCVD-0000-003-internet-exposed-bmc · Internet-exposed BMCUnscored
- InfiniBand subnet manager (OpenSM / UFM): The IB subnet manager has unilateral authority over LID assignment, routingNCVD-0000-004-infiniband-subnet-manager-opensm · InfiniBand subnet manager (OpenSM / UFM)Unscored
- RDMA / RoCE: RoCE and IB RDMA have no cryptographic authentication of the QP connection setup or of subsequentNCVD-0000-005-rdma-roce · RDMA / RoCEUnscored
- NVMe-oF over RDMA: NVMe-over-Fabrics inherits RDMA's lack of authenticationNCVD-0000-006-nvme-of-over-rdma · NVMe-oF over RDMAUnscored
- Facility power / DCIM as a class: PDUs, CRAC controllers, BMS and DCIM platforms run long-lived embedded firmware, sitNCVD-0000-007-facility-power-dcim-as-a-class · Facility power / DCIM as a classUnscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.