Database/Firmware, BMC & network fabric
Intel CSME / Converged Security and Management Engine (mask ROM): A flaw in the CSME boot ROM window before memory
Impact
A flaw in the CSME boot ROM window before memory protections engage allows code execution in the engine that is the hardware root of trust for the whole platform - it is what verifies BIOS under Boot Guard, backs Intel PTT/fTPM, and holds the chipset key from which platform-unique keys derive. Researchers demonstrated extraction of that chipset key, which forges the identity of the platform itself: EPID-based attestation, DRM, and any measurement chain rooted in CSME become untrustworthy, and the compromise is not visible from the OS at all.
Who can reach it
Local or physical access to the machine during the early boot window. On bare-metal GPU rental, a tenant with root plus a reboot is the realistic actor; on a colo floor, so is anyone with hands.
What to do
Cannot be fully fixed. The vulnerable code is in mask ROM, so no firmware update replaces it - Intel's CSME updates only narrow the exploitation window. The durable answer is hardware generations that are not affected, and until then treating CSME-rooted attestation as advisory rather than authoritative. If you sell attestation guarantees, do not root them here; root them in a discrete device you control.
References
Related entries
- Dell iDRAC9 (web interface, local file inclusion): A path-traversal / local-file-inclusion flaw lets a low-privilegeCVE-2020-5366 · Dell iDRAC9 (web interface, local file inclusion)High
- Dell iDRAC9: TOCTOU race during simultaneous web-interface access — state corruption on the BMCCVE-2021-21539 · Dell iDRAC9High
- AMD SEV-ES firmware - TMR placement in MMIO space: SEV-ES firmware does not verify that the Trusted Memory Region isCVE-2021-26332 · AMD SEV-ES firmware - TMR placement in MMIO spaceHigh
- AMD Secure Processor firmware - BIOS mailbox command bounds checking: Insufficient bounds checking while the ASPCVE-2021-26402 · AMD Secure Processor firmware - BIOS mailbox command bounds checkingHigh
- Arista EOS (service ACLs): Service ACL bypass for OpenConfig gNOI and RESTCONFCVE-2021-28507 · Arista EOS (service ACLs)High
- Dell Enterprise SONiC OS (information disclosure): An authenticated user can extract sensitive informationCVE-2021-36309 · Dell Enterprise SONiC OS (information disclosure)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.