Database/Firmware, BMC & network fabric
AMD Secure Processor Secure OS - memory buffer checking: A malicious trusted application can read and write the ASP
Impact
A malicious trusted application can read and write the ASP Secure OS's kernel virtual address space because buffer bounds are not checked at the TA boundary. That is full privilege escalation inside the secure processor - the attacker is now the security engine, not a client of it.
Who can reach it
Local, requires the ability to load a malicious trusted application into the ASP (signing-key compromise or a legitimately signed but attacker-controlled TA).
What to do
Fixed in AMD reference firmware (AGESA / SEV firmware) and delivered to you only as an OEM SBIOS/BIOS package - Dell, HPE, Supermicro, Lenovo, Gigabyte and the ODMs each rebuild and requalify AMD's AGESA drop before it ships. **Expect months, not weeks**: AMD publishes the bulletin, the OEM ships BIOS somewhere between one and six months later, and for platforms past their support window it may never arrive at all. Applying it is a full node power cycle with the host drained - not a driver reload, not a live patch. Track it as a firmware campaign per server SKU, not per kernel version, and verify afterwards by reading back the SMU/PSP firmware version rather than trusting the BIOS revision string.
References
Related entries
- Lenovo XClarity Controller (XCC) - LDAP/AD authorization: When XCC is configured to authenticate against ActiveCVE-2023-29057 · Lenovo XClarity Controller (XCC) - LDAP/AD authorizationHigh
- BMC firmware for Intel Server Boards S2600WF / S2600ST / S2600BP before 02.01.0017 and M50CYP, and OpenBMC firmwareCVE-2023-29164 · BMC firmware for Intel Server Boards S2600WF / S2600ST / S2600BP before 02.01.0017 and M50CYP, and OpenBMC firmware…High
- Linux bnxt_en driver (bnxt_fill_hw_rss_tbl): Memory out-of-bounds in the RSS indirection-table path of the Broadcom NICCVE-2024-44933 · Linux bnxt_en driver (bnxt_fill_hw_rss_tbl)High
- Linux kernel mpi3mr driver (Broadcom tri-mode 9600-series HBA/RAID) and megaraid_sas driver: Rapidly toggling PHYCVE-2024-57804 · Linux kernel mpi3mr driver (Broadcom tri-mode 9600-series HBA/RAID) and megaraid_sas driverHigh
- BullSequana XH3406/XH3515 BMC: factory reset can leave root enabled with no passwordCVE-2025-15679 · BullSequana XH3406 / XH3515 BMC (root account after factory reset)High
- AMI AptioV UEFI BIOS: A race condition in the BIOS that a skilled local attacker can drive to resource exhaustionCVE-2025-22830 · AMI AptioV UEFI BIOSHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.