Database/Firmware, BMC & network fabric
NVMe-oF over RDMA: NVMe-over-Fabrics inherits RDMA's lack of authentication
UnscoredNCVD-0000-006-nvme-of-over-rdmaFirmware, BMC & network fabricNeVerMorecurated
Impact
NVMe-over-Fabrics inherits RDMA's lack of authentication; storage targets are addressable by any host on the fabric, so a compromised tenant node can reach other tenants' namespaces. No CVE — design
Who can reach it
Fabric-local
What to do
Enforce NVMe-oF host NQN allowlisting plus DH-HMAC-CHAP authentication and separate storage fabric; costs throughput and adds provisioning complexity
References
Related entries
- Facility power / DCIM as a class: PDUs, CRAC controllers, BMS and DCIM platforms run long-lived embedded firmware, sitNCVD-0000-007-facility-power-dcim-as-a-class · Facility power / DCIM as a classUnscored
- Firmware signing-key compromise as a class: Firmware trust anchors (Boot Guard KM/BPM, UEFI PK/KEK, BMC image-signingNCVD-0000-008-firmware-signing-key-compromise · Firmware signing-key compromise as a classUnscored
- Redfish implementations (all vendors): Redfish replaced IPMI but reintroduced the same class of flaws at the HTTP layerNCVD-0000-009-redfish-implementations-all-vend · Redfish implementations (all vendors)Unscored
- KVM-over-IP / virtual media: The BMC's virtual-media function can mount an arbitrary ISO as the host's boot deviceNCVD-0000-010-kvm-over-ip-virtual-media · KVM-over-IP / virtual mediaUnscored
- Serial console servers / out-of-band access appliances: Console servers (Opengear, Lantronix, Digi and similar) holdNCVD-0000-011-serial-console-servers-out-of-ba · Serial console servers / out-of-band access appliancesUnscored
- ATA Secure Erase / NVMe Sanitize / Format NVM across SSD vendorsNCVD-2011-001-ata-secure-erase-nvme-sanitize-f · ATA Secure Erase / NVMe Sanitize / Format NVM across SSD vendors - drives that report sanitization success while…Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.