Database/Firmware, BMC & network fabric
Intel Boot Guard in Intel CSME / TXE / SPS: Insecure default initialisation in Boot Guard means the S3 resume path does
Impact
Insecure default initialisation in Boot Guard means the S3 resume path does not re-verify the boot chain, so an attacker who can modify firmware while the machine is suspended defeats verified boot. Boot Guard is the hardware root of trust the rest of your platform attestation chains to - if it does not hold on resume, it does not hold.
Who can reach it
An attacker able to modify platform firmware, typically with physical access or an existing firmware-write primitive, against a machine that suspends.
What to do
Fixed in Intel CSME/SPS firmware, which reaches you as an OEM BIOS or firmware package - not as a microcode or OS update. That means: wait for your server vendor to ship it, drain the node, flash, and reboot. OEM availability is the long pole and routinely lags the Intel advisory by one or more quarters on server platforms. Track it per platform SKU, because vendors ship these unevenly across their own product lines. Servers that never suspend are largely out of scope, which is most of a datacenter fleet - but verify rather than assume, because management controllers do use low-power states.
References
Related entries
- Intel / Solidigm SSD, SSD DC and Optane SSD firmwareCVE-2021-33077 · Intel / Solidigm SSD, SSD DC and Optane SSD firmware - control-flow flaw and uncleared debug data reachable over…Medium
- Intel Boot Guard and Intel TXT (hardware debug / INIT): Hardware debug modes and processor INIT handling can overrideCVE-2022-0004 · Intel Boot Guard and Intel TXT (hardware debug / INIT)Medium
- AMD Secure Processor secure boot - voltage fault injection (AMD-SB-4005): Voltage fault injection against the ASPCVE-2023-20589 · AMD Secure Processor secure boot - voltage fault injection (AMD-SB-4005)Medium
- Trend Micro Endpoint Encryption Full Disk Encryption (UEFI pre-boot): A signed pre-boot component that allows SecureCVE-2023-28005 · Trend Micro Endpoint Encryption Full Disk Encryption (UEFI pre-boot)Medium
- AMI AptioV UEFI BIOS (SPI flash access control): Improper access control in the BIOS that lets a local attacker makeCVE-2024-2315 · AMI AptioV UEFI BIOS (SPI flash access control)Medium
- Lenovo XClarity Administrator (LXCA) - single sign-on to XCC: Where LXCA acts as the single sign-on provider for XCCCVE-2024-45101 · Lenovo XClarity Administrator (LXCA) - single sign-on to XCCMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.