Database/Firmware, BMC & network fabric
Intel / Solidigm SSD, SSD DC and Optane SSD firmware
Impact
Two firmware defects in the same advisory, both scored 6.8 and both giving full confidentiality-plus-integrity impact to someone holding the drive. The control-flow flaw escalates privilege inside the drive controller; the second leaves debug information in the firmware that was never cleared for production, exposing internal state and enabling further escalation. Together they mean the drive controller itself is takeable - and a controller you control is a controller that can lie about sanitize, lie about encryption, and read every block regardless of Opal locking. BREAKS TENANT HANDOFF at the root: every erase-and-report guarantee in your reclaim pipeline is only as trustworthy as the firmware making the report, and here that firmware is compromisable. Also a leftover-debug-in-shipping-firmware finding, which tells you what the vendor's production hardening was actually worth on these SKUs.
Who can reach it
An unauthenticated attacker with physical access to the drive - no password, no host credential, no prior privilege. In an operator's world that means the RMA return path, a decommissioned node, a colo cage with shared access, or a supply-chain touchpoint before the drive was ever racked.
What to do
Firmware flash per SKU using Intel MAS / Solidigm Storage Tool, drive offline and node drained. Match your inventory against INTEL-SA-00563 - it covers a wide spread of Intel SSD, SSD DC, Optane SSD and Optane SSD DC families with different fixed-firmware versions each, and some end-of-support SKUs get no fix at all. Beyond patching, this is the entry that should drive a chain-of-custody policy rather than a technical one: because exploitation needs only physical possession, the highest-leverage change is to stop letting drives that held tenant data leave your control intact. Destroy media on decommission instead of reselling, negotiate destroy-in-place terms with the vendor for RMA, and treat any drive with an unexplained gap in custody as compromised at the firmware level rather than re-racking it.
References
Related entries
- Intel Boot Guard and Intel TXT (hardware debug / INIT): Hardware debug modes and processor INIT handling can overrideCVE-2022-0004 · Intel Boot Guard and Intel TXT (hardware debug / INIT)Medium
- AMD Secure Processor secure boot - voltage fault injection (AMD-SB-4005): Voltage fault injection against the ASPCVE-2023-20589 · AMD Secure Processor secure boot - voltage fault injection (AMD-SB-4005)Medium
- Trend Micro Endpoint Encryption Full Disk Encryption (UEFI pre-boot): A signed pre-boot component that allows SecureCVE-2023-28005 · Trend Micro Endpoint Encryption Full Disk Encryption (UEFI pre-boot)Medium
- AMI AptioV UEFI BIOS (SPI flash access control): Improper access control in the BIOS that lets a local attacker makeCVE-2024-2315 · AMI AptioV UEFI BIOS (SPI flash access control)Medium
- Lenovo XClarity Administrator (LXCA) - single sign-on to XCC: Where LXCA acts as the single sign-on provider for XCCCVE-2024-45101 · Lenovo XClarity Administrator (LXCA) - single sign-on to XCCMedium
- Kioxia CM6 (GPK5 and earlier), PM6 (BD0D and earlier), PM7 (C40A and earlier) enterprise NVMe/SAS SSDsCVE-2024-7726 · Kioxia CM6 (GPK5 and earlier), PM6 (BD0D and earlier), PM7 (C40A and earlier) enterprise NVMe/SAS SSDs…Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.