Database/Firmware, BMC & network fabric

KVM-over-IP / virtual media: The BMC's virtual-media function can mount an arbitrary ISO as the host's boot device
UnscoredNCVD-0000-010-kvm-over-ip-virtual-mediaFirmware, BMC & network fabriccurated
Impact
The BMC's virtual-media function can mount an arbitrary ISO as the host's boot device. Any BMC compromise therefore converts directly into arbitrary host boot, bypassing disk encryption and OS controls (CVE-2019-16649 is the concrete instance)
Who can reach it
Network / BMC
What to do
Disable virtual media in the BMC baseline except during provisioning windows, and gate the KVM/vmedia ports at the management-network edge. Costs the remote-hands workflow that most operations teams rely on
References
Related entries
- Serial console servers / out-of-band access appliances: Console servers (Opengear, Lantronix, Digi and similar) holdNCVD-0000-011-serial-console-servers-out-of-ba · Serial console servers / out-of-band access appliancesUnscored
- ATA Secure Erase / NVMe Sanitize / Format NVM across SSD vendorsNCVD-2011-001-ata-secure-erase-nvme-sanitize-f · ATA Secure Erase / NVMe Sanitize / Format NVM across SSD vendors - drives that report sanitization success while…Unscored
- ATA Secure Erase / NVMe Sanitize / Format NVM across SSD vendorsNCVD-2011-002-ata-secure-erase-nvme-sanitize-f · ATA Secure Erase / NVMe Sanitize / Format NVM across SSD vendors - drives that report sanitization success while…Unscored
- HDD and SSD controller firmware as a persistence surfaceNCVD-2015-001-hdd-and-ssd-controller-firmware · HDD and SSD controller firmware as a persistence surface - demonstrated against Seagate, Western Digital, Toshiba…Unscored
- HDD and SSD controller firmware as a persistence surfaceNCVD-2015-002-hdd-and-ssd-controller-firmware · HDD and SSD controller firmware as a persistence surface - demonstrated against Seagate, Western Digital, Toshiba…Unscored
- AMD SEV memory encryption - host-controlled guest physical to host physical mapping: The original demonstrationNCVD-2018-001-amd-sev-memory-encryption-host-c · AMD SEV memory encryption - host-controlled guest physical to host physical mappingUnscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.