GPU VulnDB

Database/Control plane, storage & DevOps

RPMB protocol message authentication subsystem in Intel TXE before 4.0.30 (replay-protected memory block)

CVE-2020-12355Control plane, storage & DevOpsINTEL-SA-00391curated

Impact

Capture-replay authentication bypass in RPMB - the mechanism that is supposed to make firmware anti-rollback and monotonic-counter state tamper-evident. Break RPMB and you break rollback protection: an attacker can replay old, signed state to roll firmware back to a known-vulnerable version, or to reset counters that firmware relies on to detect tampering. The operator consequence is that 'we patched that' stops being verifiable from the platform itself, and a node that you believe is on current firmware can be silently downgraded and left that way through a tenant handoff.

Who can reach it

Physical access to the platform, capturing and replaying RPMB traffic. Relevant for hardware that passes through untrusted hands - shared cages, remote-hands, RMA and resale channels, and any secondhand GPU capacity you have taken on.

What to do

TXE/CSME firmware update from the OEM bundle, host reboot and drain. More importantly, stop treating the platform's own report of its firmware version as authoritative: read firmware versions out of band via the BMC and compare against an externally held inventory, and re-flash the full firmware stack on any node that has been out of your physical custody before it re-enters a tenant pool.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.