Database/Firmware, BMC & network fabric
IPMI over LAN as a protocol: IPMI has no transport confidentiality guarantees worth relying on, weak session handling
UnscoredNCVD-0000-002-ipmi-over-lan-as-a-protocolFirmware, BMC & network fabriccurated
Impact
IPMI has no transport confidentiality guarantees worth relying on, weak session handling, and per-vendor implementations that diverge from spec. Every BMC on the fleet speaks it by default
Who can reach it
Network, management VLAN
What to do
Fleet policy decision to disable IPMI-over-LAN and force Redfish-only; costs a rewrite of provisioning/monitoring tooling and loses compatibility with older ODM chassis
References
Related entries
- Internet-exposed BMC: Shodan-visible BMCs are a recurring finding at colo/neocloud buildoutsNCVD-0000-003-internet-exposed-bmc · Internet-exposed BMCUnscored
- InfiniBand subnet manager (OpenSM / UFM): The IB subnet manager has unilateral authority over LID assignment, routingNCVD-0000-004-infiniband-subnet-manager-opensm · InfiniBand subnet manager (OpenSM / UFM)Unscored
- RDMA / RoCE: RoCE and IB RDMA have no cryptographic authentication of the QP connection setup or of subsequentNCVD-0000-005-rdma-roce · RDMA / RoCEUnscored
- NVMe-oF over RDMA: NVMe-over-Fabrics inherits RDMA's lack of authenticationNCVD-0000-006-nvme-of-over-rdma · NVMe-oF over RDMAUnscored
- Facility power / DCIM as a class: PDUs, CRAC controllers, BMS and DCIM platforms run long-lived embedded firmware, sitNCVD-0000-007-facility-power-dcim-as-a-class · Facility power / DCIM as a classUnscored
- Firmware signing-key compromise as a class: Firmware trust anchors (Boot Guard KM/BPM, UEFI PK/KEK, BMC image-signingNCVD-0000-008-firmware-signing-key-compromise · Firmware signing-key compromise as a classUnscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.