Database/Firmware, BMC & network fabric
AMD Secure Processor secure boot - voltage fault injection (AMD-SB-4005): Voltage fault injection against the ASP
Impact
Voltage fault injection against the ASP defeats its secure boot, yielding arbitrary code execution on the secure processor and extraction of fTPM-sealed secrets - the published work pulls BitLocker keys out. The affected list is Zen 1/2/3 **client** parts and EPYC is not on it, but the technique is the reason to read this entry: a datacenter operator with hardware in colocation, in transit, or coming back from RMA has to assume physical access to some nodes by someone.
Who can reach it
Physical access plus specialised fault-injection hardware. Not remote, not local-software.
What to do
Fixed in AGESA/PI firmware for the affected client parts - OEM BIOS package, drain and power cycle. For a server fleet the practical answer is not patching but physical control: tamper-evident handling, chain of custody for RMAs and redeployments, and not trusting fTPM-sealed secrets on any node that has left your custody. AMD's position on the server analogue (AMD-SB-3028, voltage fault injection against SEV VMs on EPYC 7272) is **WONTFIX** - physical attacks are declared outside the SEV-SNP threat model, so there is no patch coming for the server case at all.
References
Related entries
- Trend Micro Endpoint Encryption Full Disk Encryption (UEFI pre-boot): A signed pre-boot component that allows SecureCVE-2023-28005 · Trend Micro Endpoint Encryption Full Disk Encryption (UEFI pre-boot)Medium
- AMI AptioV UEFI BIOS (SPI flash access control): Improper access control in the BIOS that lets a local attacker makeCVE-2024-2315 · AMI AptioV UEFI BIOS (SPI flash access control)Medium
- Lenovo XClarity Administrator (LXCA) - single sign-on to XCC: Where LXCA acts as the single sign-on provider for XCCCVE-2024-45101 · Lenovo XClarity Administrator (LXCA) - single sign-on to XCCMedium
- Kioxia CM6 (GPK5 and earlier), PM6 (BD0D and earlier), PM7 (C40A and earlier) enterprise NVMe/SAS SSDsCVE-2024-7726 · Kioxia CM6 (GPK5 and earlier), PM6 (BD0D and earlier), PM7 (C40A and earlier) enterprise NVMe/SAS SSDs…Medium
- NVIDIA ConnectX and BlueField: a VF holder can wedge the adapter through a control register commandCVE-2025-33207 · NVIDIA ConnectX / BlueField firmware (control register interface reachable from a VF)Medium
- Intel processors, exploitable from within VMX non-root (guest) operation - INTEL-SA-01420: Shared microarchitecturalCVE-2025-35979 · Intel processors, exploitable from within VMX non-root (guest) operation - INTEL-SA-01420Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.