GPU VulnDB

Database/Firmware, BMC & network fabric

GRUB2 (USB device initialization): Out-of-bounds write in grub_usb_device_initialize from a malicious USB descriptor

CVE-2020-25647Firmware, BMC & network fabriccurated

Impact

Out-of-bounds write in grub_usb_device_initialize from a malicious USB descriptor. In a datacenter this is not a 'someone walks up with a USB stick' story - the BMC presents virtual media as a USB device, so anyone with BMC credentials can trigger it entirely remotely.

Who can reach it

Physical USB, or - the one that matters - BMC virtual media, which turns this into a remote attack for anyone on the management VLAN with iDRAC/iLO/XCC credentials.

What to do

grub2 package update + reboot. Meaningful compensating control: disable virtual media on the BMC where you do not use it for provisioning, and keep the management network off any tenant-reachable path.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.