Database/Firmware, BMC & network fabric
BMC firmware on Intel server boards, compute modules and systems - SMBus access control: An attacker
Impact
An attacker with administrative privileges on the BMC can issue unauthorized reads and writes on the platform SMBus. SMBus is the wire that reaches the power supplies (PMBus), the voltage regulators, the DIMM SPD EEPROMs and the temperature sensors. Write access there is a physical-consequence primitive: reprogram a VR or PSU setpoint, corrupt SPD so DIMMs no longer train, or falsify thermal telemetry so the platform does not throttle. On a dense GPU node this can mean a forced power-off, a bricked-until-RMA board, or a thermal event that the DCIM layer never sees coming. It is also persistence - SMBus-attached EEPROM contents survive any host reimage and therefore cross tenant handoff.
Who can reach it
Administrative access to the BMC. That is reached from the out-of-band management network, from any credential reuse across the IPMI/Redfish fleet, or from the host itself via the KCS/host interface if you have not disabled it - which means a tenant with root on a bare-metal node is one BMC bug away from the SMBus.
What to do
BMC firmware update from Intel or the board OEM (Intel server boards, and the ODMs building on them - Quanta, Wiwynn, Supermicro). BMC flashes generally do not require a host reboot, which makes this one of the cheaper firmware rollouts, but the update must be staged per board family. The structural controls matter more: put the BMC on a network no tenant can reach, use unique per-node BMC credentials, and disable the host-to-BMC KCS/host interface on bare-metal SKUs so a tenant with root cannot talk to the BMC at all.
References
Related entries
- GRUB2: Buffer overflow in `grub.cfg` parsing allowing Secure Boot bypass and arbitrary code execution inside GRUBCVE-2020-10713 · GRUB2High
- GRUB2 (direct kernel boot without shim): When GRUB is booted directly by UEFI rather than chained through shim, it doesCVE-2020-15705 · GRUB2 (direct kernel boot without shim)High
- Cisco NX-OS (BGP MD5 authentication): BGP MD5 authentication can be bypassed, so an attacker can bring up a BGP sessionCVE-2020-3165 · Cisco NX-OS (BGP MD5 authentication)High
- Dell client and server BIOS - NVMe drive password (SED credential) defeated by resetting the BIOS passwordCVE-2021-21522 · Dell client and server BIOS - NVMe drive password (SED credential) defeated by resetting the BIOS password via the…High
- Insyde InsydeH2O (FwBlockServiceSmm): Software SMI services reachable through EFI_SMM_COMMUNICATION_PROTOCOL neverCVE-2021-33627 · Insyde InsydeH2O (FwBlockServiceSmm)High
- InsydeH2O: HDD password is stored in plaintext in a UEFI variable readable from the OSCVE-2021-38489 · InsydeH2O UEFI firmware (HDD password stored in a UEFI variable)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.