Database/Firmware, BMC & network fabric
NVIDIA DGX BMC (AMI firmware): CSRF in the BMC web application
Impact
CSRF in the BMC web application. An operator with a BMC session open in a browser can be made to execute BMC actions by loading an attacker's page - disclosure or code execution against out-of-band management without the attacker ever needing network reach to the BMC themselves. DGX-1 before BMC 3.38.30.
Who can reach it
Any attacker who can get a logged-in BMC administrator to visit a web page. The attacker needs no route to the management network at all - the admin's browser is the route.
What to do
Flash the DGX BMC firmware from NVIDIA's DGX firmware update container (DGX-1 to 3.38.30 or later, DGX-2 to 1.06.06 or later; DGX A100 per the bulletin's table). A BMC flash does not require the host OS to reboot but drops out-of-band management for several minutes and NVIDIA recommends a host power cycle afterwards, so treat it as a per-node maintenance window. Rotate every BMC and IPMI credential after the flash - flashing does not invalidate secrets an attacker already pulled. Keep BMCs on an isolated management VLAN with no route from tenant or job networks.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.