GPU VulnDB

Database/Firmware, BMC & network fabric

Lanner IAC-AST2500A BMC firmware: The attacker rewrites who is permitted to use KVM and virtual media on the BMC

CVE-2021-44776Firmware, BMC & network fabriccurated

Impact

The attacker rewrites who is permitted to use KVM and virtual media on the BMC - which is to say they grant themselves console access and the ability to attach a boot image. Even at a medium score this is a direct route to the two BMC capabilities that matter most to an operator: watching a tenant's console, and booting the node into attacker-supplied media. It is also a quieter attack than the overflow bugs, because it leaves the BMC running normally with an altered permission set rather than crashing anything. Broken access control in the SubNet_handler_func function of spx_restservice, allowing an attacker to change the security access rights governing KVM and virtual media.

Who can reach it

Network access to the BMC REST service with sufficient standing to invoke the subnet handler. Reachable from the out-of-band management network.

What to do

Firmware flash, subject to the same Lanner sourcing problem as the rest of the cluster. Because this bug manipulates configuration rather than corrupting memory, it leaves auditable state: check the KVM and virtual-media permission settings on every IAC-AST2500A BMC against your intended baseline, and alert on changes. Where fixed firmware is unobtainable, disabling virtual media and KVM outright on the BMC - where the platform permits it - removes the capability the attacker is trying to grant themselves.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.