Database/Firmware, BMC & network fabric
Intel Server Board / Server System / Compute Module platform firmware: Improper memory initialisation in platform
Impact
Improper memory initialisation in platform sample/silicon reference firmware on Intel server boards, allowing privilege escalation. Reference firmware defects propagate into whatever the OEM built on top of it, so the affected population is wider than Intel-branded boards.
Who can reach it
Privileged local access on the host.
What to do
Fixed in platform BIOS/UEFI firmware. That means an OEM release, a per-node drain, a flash and a cold reboot - and OEM availability commonly lags the Intel advisory by quarters on server boards. There is no microcode or OS-level shortcut for this class; budget it as a fleet-wide maintenance campaign, not a patch.
References
Related entries
- Intel Xeon D / Xeon Scalable system firmware, Server Board and Server System: A buffer overflow in system firmwareCVE-2019-0119 · Intel Xeon D / Xeon Scalable system firmware, Server Board and Server SystemMedium
- Intel SGX / dynamic voltage and frequency scaling interface: Undervolting the CPU through the privilegedCVE-2019-11157 · Intel SGX / dynamic voltage and frequency scaling interfaceMedium
- NVIDIA DGX BMC (AMI firmware): The BMC does not validate the RSA-1024 public key used to verify firmware signaturesCVE-2020-11488 · NVIDIA DGX BMC (AMI firmware)Medium
- GRUB2 (cutmem command): The cutmem command was not gated by Secure Boot lockdown, so a privileged user could carveCVE-2020-27779 · GRUB2 (cutmem command)Medium
- Intel Ethernet 700 Series Controller firmware (access control): Insufficient access control inside 700-series NICCVE-2020-8692 · Intel Ethernet 700 Series Controller firmware (access control)Medium
- Intel BIOS firmware: Insufficient control-flow management in Intel BIOS firmware lets a privileged user escalateCVE-2021-0157 · Intel BIOS firmwareMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.