Database/Firmware, BMC & network fabric
Dell client and server BIOS - NVMe drive password (SED credential) defeated by resetting the BIOS password
Impact
The BIOS-managed NVMe drive password - the credential many operators rely on to keep a locked drive locked - can be defeated by resetting the BIOS password through the manageability interface, giving access to data on the NVMe device. The paired issue removes the limit on failed NVMe password attempts, so an administrator can brute-force the drive password instead. BREAKS TENANT HANDOFF wherever platform-level drive locking is your control: the lock lives in a BIOS that a local administrator can reset, so the drive credential inherits the security of the BIOS password rather than of the drive. This is the systems-integration failure mode of SEDs - the drive firmware may be perfectly sound while the platform that holds its credential hands it away.
Who can reach it
A local authenticated user with elevated privilege on the host - which on bare metal means the tenant you just rented the box to, if they have BIOS/manageability reach. The brute-force variant requires local administrator access.
What to do
Apply the Dell BIOS updates named in Dell's advisory for the affected client and PowerEdge platforms; this is a host BIOS flash, so it needs a reboot and a maintenance window per node but not a drive teardown. Then fix the design, not just the bug: do not use BIOS-held NVMe passwords as your tenant-separation mechanism on bare metal, because the whole scheme assumes the tenant cannot reach platform firmware, and on a rented bare-metal node that assumption is false by definition. Lock down the manageability interface, set and monitor BIOS admin passwords, and move the actual data protection to LUKS/dm-crypt with a key your control plane holds and destroys at reclaim - a key the tenant's BIOS access cannot reach.
References
Related entries
- Insyde InsydeH2O (FwBlockServiceSmm): Software SMI services reachable through EFI_SMM_COMMUNICATION_PROTOCOL neverCVE-2021-33627 · Insyde InsydeH2O (FwBlockServiceSmm)High
- InsydeH2O: HDD password is stored in plaintext in a UEFI variable readable from the OSCVE-2021-38489 · InsydeH2O UEFI firmware (HDD password stored in a UEFI variable)High
- GRUB2 (shim_lock verifier): The shim_lock verifier let non-kernel files through, so an attacker could get unsignedCVE-2022-28735 · GRUB2 (shim_lock verifier)High
- shim (handle_image PE loader): Buffer overflow in shim's own image loaderCVE-2022-28737 · shim (handle_image PE loader)High
- Insyde InsydeH2O (UsbCoreDxe, untrusted pointer use): UsbCoreDxe uses pointers it was handed without establishing theyCVE-2022-29275 · Insyde InsydeH2O (UsbCoreDxe, untrusted pointer use)High
- Insyde InsydeH2O (AhciBusDxe, untrusted SMI inputs): SMI functions in the AHCI/SATA driver consume untrusted inputsCVE-2022-29276 · Insyde InsydeH2O (AhciBusDxe, untrusted SMI inputs)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.