Database/Firmware, BMC & network fabric
Intel Server Platform Services (SPS) firmware: Active debug code left enabled in shipped SPS firmware lets
Impact
Active debug code left enabled in shipped SPS firmware lets an authenticated user escalate privilege. SPS is the server variant of the management engine - it is the component running on your Xeon nodes, not the consumer CSME - so debug code in production firmware is squarely a datacenter problem.
Who can reach it
Authenticated local access on an affected server.
What to do
Fixed in Intel SPS firmware, which reaches you as an OEM BIOS or firmware package - not as a microcode or OS update. That means: wait for your server vendor to ship it, drain the node, flash, and reboot. OEM availability is the long pole and routinely lags the Intel advisory by one or more quarters on server platforms. Track it per platform SKU, because vendors ship these unevenly across their own product lines.
References
Related entries
- Linux kernel (drivers/infiniband/hw/hfi1): The node panics when the fabric link goes down while any sender is waitingCVE-2022-49931 · Linux kernel (drivers/infiniband/hw/hfi1)High
- Insyde InsydeH2O (IhisiSmm SMI handler): A malicious host OS calls an Insyde SMI handler with malformed argumentsCVE-2023-22612 · Insyde InsydeH2O (IhisiSmm SMI handler)High
- Dell PowerEdge Server BIOS (privilege management): An improper privilege-management flaw in PowerEdge BIOSCVE-2023-32460 · Dell PowerEdge Server BIOS (privilege management)High
- Supermicro BMC web interface CGI endpoints on X11 and M11 based boards with BMC firmware before 3.17.02CVE-2023-33412 · Supermicro BMC web interface CGI endpoints on X11 and M11 based boards with BMC firmware before 3.17.02High
- Supermicro BMC configuration functionality on X11 and M11 based boards through firmware 3.17.02: Arbitrary commandCVE-2023-33413 · Supermicro BMC configuration functionality on X11 and M11 based boards through firmware 3.17.02High
- EDK II NetworkPkg (DHCPv6 DNS Servers option handling): A crafted DNS Servers option inside a DHCPv6 AdvertiseCVE-2023-45234 · EDK II NetworkPkg (DHCPv6 DNS Servers option handling)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.