Database/Firmware, BMC & network fabric

AMI MegaRAC SPx 12 / SPx 13 (BMC): Untrusted pointer dereference in the BMC that a low-privileged actor can turn
Impact
Untrusted pointer dereference in the BMC that a low-privileged actor can turn into code execution or a controller crash. As a second-stage bug it is how an attacker who already got a foothold - a read-only monitoring account, a low-privilege Redfish user, or a partial exploit of one of the network bugs - upgrades to full BMC control and firmware persistence.
Who can reach it
AMI's CVSS vector scores this as local access with low privileges required, while AMI's own prose calls it reachable from the local network; treat it as reachable by anyone who already holds a low-privilege position on or adjacent to the BMC. In a fleet, the realistic precondition is a leaked low-tier BMC credential - which is common, because BMC passwords are frequently shared across a whole rack or SKU by the provisioning system.
What to do
Firmware flash to SPx_12.7 / SPx_13.6, out-of-band per node, ODM-gated. Alongside the flash, the cheap wins are config-only: give every BMC a unique password (kill any shared default from the deployment template), delete unused BMC accounts, and drop any monitoring account down to the minimum Redfish role.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.