Database/Firmware, BMC & network fabric

Redfish implementations (all vendors): Redfish replaced IPMI but reintroduced the same class of flaws at the HTTP layer
NCVD-0000-009-redfish-implementations-all-vendFirmware, BMC & network fabriccurated
Impact
Redfish replaced IPMI but reintroduced the same class of flaws at the HTTP layer — CVE-2024-54085, CVE-2023-34330, CVE-2023-25191/25192, CVE-2018-15774 are all Redfish-surface bugs. The spec mandates no minimum implementation assurance, and every ODM ships its own stack
Who can reach it
Network / management VLAN
What to do
Treat Redfish as an untrusted-by-default surface: mTLS or a management-plane proxy in front of every BMC, per-node unique credentials, and no direct operator access. This is architecture work, not patching
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.