Database/Control plane, storage & DevOps
Intel SPS (HECI subsystem compartmentalisation): Insufficient compartmentalisation in the HECI interface
Impact
Insufficient compartmentalisation in the HECI interface - the host-to-management-engine channel - on Server Platform Services firmware. HECI is the door between the OS and the management engine, so weak compartmentalisation there means host-side code reaches further into the engine than it should.
Who can reach it
Local access on the host with the ability to talk to the HECI device.
What to do
Fixed in Intel CSME/SPS firmware, which reaches you as an OEM BIOS or firmware package - not as a microcode or OS update. That means: wait for your server vendor to ship it, drain the node, flash, and reboot. OEM availability is the long pole and routinely lags the Intel advisory by one or more quarters on server platforms. Track it per platform SKU, because vendors ship these unevenly across their own product lines.
References
Related entries
- Dell CloudLink (cluster component exception handling): A highly privileged remote attacker performs unauthorizedCVE-2024-38482 · Dell CloudLink (cluster component exception handling)Medium
- AMD Versal Adaptive SoC - PLM runtime services address validation: The Platform Loader and Manager firmware on AMDCVE-2025-0037 · AMD Versal Adaptive SoC - PLM runtime services address validationMedium
- Ansible automation-controller: unvalidated system-job "days" value injects arguments into control-node awx-manageCVE-2026-84724 · Red Hat Ansible Automation Platform automation-controller (system-job launch, awx-manage argument vector)Medium
- HTCondor (condor_schedd, GSI/VOMS extension parsing): An authenticated user crashes the schedd by feeding it malformedCVE-2017-16816 · HTCondor (condor_schedd, GSI/VOMS extension parsing)Medium
- GlusterFS (dict_unserialize): A negative key length in a serialized dict makes the server read memory from elsewhere inCVE-2018-10911 · GlusterFS (dict_unserialize)Medium
- Ceph CephX authentication protocol: The CephX signature calculation can be bypassed, so an on-path attacker can alterCVE-2018-1129 · Ceph CephX authentication protocolMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.