Database/Firmware, BMC & network fabric
RDMA / RoCE: RoCE and IB RDMA have no cryptographic authentication of the QP connection setup or of subsequent
UnscoredNCVD-0000-005-rdma-roceFirmware, BMC & network fabricReDMArkcurated
Impact
RoCE and IB RDMA have no cryptographic authentication of the QP connection setup or of subsequent RDMA reads/writes; an on-fabric attacker can inject and impersonate, and remote memory reads bypass the target CPU entirely. No CVE — it is the RDMA specification
Who can reach it
Fabric-local, tenant-to-tenant
What to do
Requires fabric-level isolation (per-tenant pkeys / VXLAN-isolated RoCE domains) or PSP/IPsec offload on the NIC. Shared-fabric multi-tenancy without this is an unmitigated tenant-to-tenant read primitive
References
Related entries
- NVMe-oF over RDMA: NVMe-over-Fabrics inherits RDMA's lack of authenticationNCVD-0000-006-nvme-of-over-rdma · NVMe-oF over RDMAUnscored
- Facility power / DCIM as a class: PDUs, CRAC controllers, BMS and DCIM platforms run long-lived embedded firmware, sitNCVD-0000-007-facility-power-dcim-as-a-class · Facility power / DCIM as a classUnscored
- Firmware signing-key compromise as a class: Firmware trust anchors (Boot Guard KM/BPM, UEFI PK/KEK, BMC image-signingNCVD-0000-008-firmware-signing-key-compromise · Firmware signing-key compromise as a classUnscored
- Redfish implementations (all vendors): Redfish replaced IPMI but reintroduced the same class of flaws at the HTTP layerNCVD-0000-009-redfish-implementations-all-vend · Redfish implementations (all vendors)Unscored
- KVM-over-IP / virtual media: The BMC's virtual-media function can mount an arbitrary ISO as the host's boot deviceNCVD-0000-010-kvm-over-ip-virtual-media · KVM-over-IP / virtual mediaUnscored
- Serial console servers / out-of-band access appliances: Console servers (Opengear, Lantronix, Digi and similar) holdNCVD-0000-011-serial-console-servers-out-of-ba · Serial console servers / out-of-band access appliancesUnscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.