Database/Firmware, BMC & network fabric

Insyde InsydeH2O (MebxConfiguration DXE driver): A UEFI variable that the OS can write is read back by BIOS code
Impact
A UEFI variable that the OS can write is read back by BIOS code into a fixed-size stack buffer without a length check. Set the variable from the OS, reboot, and your code runs during DXE - before Secure Boot has finished deciding what is allowed to run. The persistence mechanism is the variable store itself, which means the implant re-arms on every boot and survives disk replacement entirely.
Who can reach it
Local admin/root on the host OS with the ability to write UEFI variables (standard on Linux via efivarfs and on Windows via SetFirmwareEnvironmentVariable), then one reboot.
What to do
OEM BIOS update built on the fixed Insyde kernel. Firmware flash, reboot per node. There is no config toggle. Detection is possible in the interim: monitor for unexpected writes to the relevant UEFI variables from the OS, and make efivarfs read-only where your workload does not need it. On a fleet, treat any node where firmware variables changed outside a maintenance window as suspect.
References
Related entries
- AMI MegaRAC SPx (Dynamic Redfish Extension): Code injection executed via the Dynamic Redfish Extension interfaceCVE-2023-34330 · AMI MegaRAC SPx (Dynamic Redfish Extension)High
- Signed third-party UEFI application (Howyar Reloader and OEM rebrands): A Microsoft-signed UEFI recovery applicationCVE-2024-7344 · Signed third-party UEFI application (Howyar Reloader and OEM rebrands)High
- Insyde InsydeH2O (H19Int15CallbackSmm, combined DXE/SMM driver): An unchecked output buffer in a combined DXE/SMMCVE-2025-10451 · Insyde InsydeH2O (H19Int15CallbackSmm, combined DXE/SMM driver)High
- Intel Server Firmware Update Utility (SysFwUpdt) and Server Configuration Utility before version 16.0.12: ImproperCVE-2025-25210 · Intel Server Firmware Update Utility (SysFwUpdt) and Server Configuration Utility before version 16.0.12High
- AMI AptioV UEFI BIOS (SMM): A write-what-where primitive plus an information leak in System Management ModeCVE-2025-33045 · AMI AptioV UEFI BIOS (SMM)High
- Broadcom NetXtreme-E network adapter firmware: A high-severity flaw in the firmware of Broadcom NetXtreme-E adaptersCVE-2025-56547 · Broadcom NetXtreme-E network adapter firmwareHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.