GPU VulnDB

Database/Firmware, BMC & network fabric

shim (HTTP boot): Out-of-bounds write from a crafted HTTP response during network boot

CVE-2023-40547Firmware, BMC & network fabriccurated

Impact

Out-of-bounds write from a crafted HTTP response during network boot — full system compromise at the pre-boot stage, before any OS security control exists

Who can reach it

Adjacent network, MITM on the boot server or a compromised PXE/HTTP boot server

What to do

New signed shim rollout plus dbx revocation of the old one. Directly relevant to neoclouds because netboot provisioning is the standard bare-metal reimaging path — the provisioning network is the attack surface

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.