Database/Firmware, BMC & network fabric
shim (HTTP boot): Out-of-bounds write from a crafted HTTP response during network boot
CVE-2023-40547Firmware, BMC & network fabriccurated
Impact
Out-of-bounds write from a crafted HTTP response during network boot — full system compromise at the pre-boot stage, before any OS security control exists
Who can reach it
Adjacent network, MITM on the boot server or a compromised PXE/HTTP boot server
What to do
New signed shim rollout plus dbx revocation of the old one. Directly relevant to neoclouds because netboot provisioning is the standard bare-metal reimaging path — the provisioning network is the attack surface
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.