GPU VulnDB

Database/Firmware, BMC & network fabric

AMI MegaRAC SPx 12 / SPx 13 (BMC web session management): Session fixation combined with sessions that never properly

CVE-2021-46279Firmware, BMC & network fabricAMI-SA-2022001Nozomi Labs BMC firmware researchcurated

Impact

Session fixation combined with sessions that never properly expire. An attacker can plant a session identifier, wait for an administrator to authenticate with it, and inherit a live admin session on the BMC - power control, console, virtual media, firmware update. The never-expiring half means stolen sessions stay valid long after the admin walked away, so a token lifted from a browser, a proxy log or a shared jump host keeps working for as long as the attacker wants it.

Who can reach it

Network access to the BMC web interface plus getting an administrator to interact with an attacker-supplied session - a link, a shared workstation, or a proxy on the management path. High complexity, no credentials required.

What to do

Firmware flash to SPx_12-update-7.00 / SPx_13-update-5.00 or later, out-of-band per node, ODM-gated. Config-only mitigations that help immediately: restrict BMC web access to a bastion, do not let admins browse anything else from that host, and force logout rather than closing the tab - the sessions this bug leaves behind are the ones that never got explicitly ended.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.