Database/Firmware, BMC & network fabric
AMD EPYC / Ryzen - Platform Security Processor privilege escalation: A direct privilege escalation into the Platform
Impact
A direct privilege escalation into the Platform Security Processor on EPYC server parts. The PSP holds the platform's root of trust, fTPM state and SEV key material, so an attacker who escalates into it owns the security posture of the whole node beneath the hypervisor. Nothing the OS or the hypervisor can do detects or contains it.
Who can reach it
Local, administrator privilege.
What to do
Fixed in AMD reference firmware (AGESA / PSP / SEV firmware) and delivered only as an OEM SBIOS/BIOS package - Dell, HPE, Supermicro, Lenovo and the ODMs each rebuild and requalify AMD's AGESA drop before shipping. **Expect one to six months of OEM lag**, and on end-of-support platforms expect nothing. Applying it is a drain plus full power cycle, not a driver reload. Verify by reading back the PSP/SMU firmware version afterwards rather than trusting the BIOS version string.
References
Related entries
- APC Smart-UPS SmartConnect family (SMT, SMC, SMTL, SCL, SMX series) - cloud-connected UPS firmware: A heap overflow inCVE-2022-22805 · APC Smart-UPS SmartConnect family (SMT, SMC, SMTL, SCL, SMX series) - cloud-connected UPS firmwareCritical
- APC Smart-UPS SmartConnect family (SMT, SMC, SMTL, SCL, SMX series) - TLS state machine: A TLS authentication bypass byCVE-2022-22806 · APC Smart-UPS SmartConnect family (SMT, SMC, SMTL, SCL, SMX series) - TLS state machineCritical
- Dell Enterprise SONiC (authentication): A critical step in authentication is missing, so an unauthenticated remoteCVE-2024-45764 · Dell Enterprise SONiC (authentication)Critical
- Arista EOS OSPFv3: crafted packet restarts the routing agentCVE-2026-73455 · Arista EOS (OSPFv3 routing agent)High
- Linux kernel InfiniBand uverbs (ib_uverbs / ib_umem_get, drivers/infiniband/core/umem.c): The canonical RDMA isolationCVE-2014-8159 · Linux kernel InfiniBand uverbs (ib_uverbs / ib_umem_get, drivers/infiniband/core/umem.c)High
- Dell iDRAC7 / iDRAC8 firmware before 2.40.40.40 - racadm CLI string injection: A string injection escapes theCVE-2016-5685 · Dell iDRAC7 / iDRAC8 firmware before 2.40.40.40 - racadm CLI string injectionHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.