Database/Firmware, BMC & network fabric

OpenBMC bmcweb mTLS client-certificate UPN validation: Where mTLS is configured, bmcweb matches the certificate's UPN
Impact
Where mTLS is configured, bmcweb matches the certificate's UPN by walking dot-separated labels with no bound. A certificate issued for user@com authenticates against any host under that TLD, and a parent-domain certificate authenticates against every child deployment. For an operator running mTLS across a fleet - which is the hardened configuration, chosen by the most security-conscious teams - this means one certificate from anywhere in the hierarchy authenticates to every BMC in it, silently, with no failed-auth log to notice. It is the rare bug that punishes you specifically for having done the harder thing.
Who can reach it
Requires mTLS to be enabled on the BMC (not the default) and possession of any certificate the BMC's trust store chains to, including one issued for a parent domain or a different deployment. Network access to the BMC's HTTPS port.
What to do
Unpatched at disclosure. An April 2026 commit fixed only case-insensitivity in the comparison and left the suffix-walking logic intact, so do not assume a recent bmcweb clears it. If you run mTLS on BMCs, audit which CAs are in each BMC's trust store and narrow them to a per-fleet issuing CA that signs nothing else - that is a config-only change and is the effective mitigation today. Do not put a broadly-scoped corporate CA in a BMC trust store. A real fix will require a BMC firmware flash once upstream lands one.
References
Related entries
- Cisco NX-OS CLI: CLI command injection giving root-level execution on the switch OS for an authenticated adminCVE-2017-12334 · Cisco NX-OS CLIMedium
- Intel Server Board / Server System / Compute Module platform firmware: Improper memory initialisation in platformCVE-2018-12204 · Intel Server Board / Server System / Compute Module platform firmwareMedium
- Intel Xeon D / Xeon Scalable system firmware, Server Board and Server System: A buffer overflow in system firmwareCVE-2019-0119 · Intel Xeon D / Xeon Scalable system firmware, Server Board and Server SystemMedium
- Intel SGX / dynamic voltage and frequency scaling interface: Undervolting the CPU through the privilegedCVE-2019-11157 · Intel SGX / dynamic voltage and frequency scaling interfaceMedium
- NVIDIA DGX BMC (AMI firmware): The BMC does not validate the RSA-1024 public key used to verify firmware signaturesCVE-2020-11488 · NVIDIA DGX BMC (AMI firmware)Medium
- GRUB2 (cutmem command): The cutmem command was not gated by Secure Boot lockdown, so a privileged user could carveCVE-2020-27779 · GRUB2 (cutmem command)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.