Database/Firmware, BMC & network fabric
AMD Secure Processor (Ryzen / Ryzen Pro / Ryzen Mobile): Insufficient access control on the Secure Processor lets code
Impact
Insufficient access control on the Secure Processor lets code already running with OS administrator rights reach into the AMD Secure Processor and execute there. The ASP sits below the hypervisor and below Secure Boot, so once an attacker is inside it, everything the platform's security rests on - memory encryption keys, fTPM state, boot measurements - is theirs. On a shared host this is the end of any isolation guarantee you were making to tenants, and the compromise survives an OS reinstall.
Who can reach it
Local, requires OS administrator/root plus the ability to flash or load a signed driver. Not remotely reachable. Realistically this is a post-exploitation depth charge: an attacker who already owns the host uses it to get persistence you cannot wash out.
What to do
Fixed in AMD reference firmware (AGESA / SEV firmware) and delivered to you only as an OEM SBIOS/BIOS package - Dell, HPE, Supermicro, Lenovo, Gigabyte and the ODMs each rebuild and requalify AMD's AGESA drop before it ships. **Expect months, not weeks**: AMD publishes the bulletin, the OEM ships BIOS somewhere between one and six months later, and for platforms past their support window it may never arrive at all. Applying it is a full node power cycle with the host drained - not a driver reload, not a live patch. Track it as a firmware campaign per server SKU, not per kernel version, and verify afterwards by reading back the SMU/PSP firmware version rather than trusting the BIOS revision string. AMD's fix was a PSP firmware update carried in AGESA. Note this batch (the CTS-Labs disclosures) targeted client Ryzen silicon rather than EPYC; verify against your actual server SKU before spending a maintenance window on it.
References
Related entries
- AMD Secure Processor (Ryzen / Ryzen Pro): The same class of Secure Processor access-control failure as RYZENFALL-1CVE-2018-8932 · AMD Secure Processor (Ryzen / Ryzen Pro)Critical
- Promontory chipset firmware (AMD Ryzen / Ryzen Pro platforms): A backdoor in the Promontory chipset firmware. TheCVE-2018-8934 · Promontory chipset firmware (AMD Ryzen / Ryzen Pro platforms)Critical
- AMD EPYC / Ryzen - Platform Security Processor privilege escalation: A direct privilege escalation into the PlatformCVE-2018-8936 · AMD EPYC / Ryzen - Platform Security Processor privilege escalationCritical
- APC Smart-UPS SmartConnect family (SMT, SMC, SMTL, SCL, SMX series) - cloud-connected UPS firmware: A heap overflow inCVE-2022-22805 · APC Smart-UPS SmartConnect family (SMT, SMC, SMTL, SCL, SMX series) - cloud-connected UPS firmwareCritical
- APC Smart-UPS SmartConnect family (SMT, SMC, SMTL, SCL, SMX series) - TLS state machine: A TLS authentication bypass byCVE-2022-22806 · APC Smart-UPS SmartConnect family (SMT, SMC, SMTL, SCL, SMX series) - TLS state machineCritical
- Dell Enterprise SONiC (authentication): A critical step in authentication is missing, so an unauthenticated remoteCVE-2024-45764 · Dell Enterprise SONiC (authentication)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.