Database/Firmware, BMC & network fabric

Insyde InsydeH2O (IhisiSmm SMI handler): A malicious host OS calls an Insyde SMI handler with malformed arguments
Impact
A malicious host OS calls an Insyde SMI handler with malformed arguments and corrupts SMM memory. IHISI is Insyde's own firmware-services interface, used by BIOS update and configuration tooling, so it is reachable by design from the OS - the bug is that it trusts what it is told. Successful exploitation is ring -2 code execution: firmware persistence, attestation you can no longer believe, and a foothold under the hypervisor.
Who can reach it
Local admin/root on the host OS invoking the IHISI SMI interface with crafted arguments.
What to do
OEM BIOS update built on the fixed Insyde kernel (5.0-5.5 affected). Firmware flash plus one reboot per node. No config workaround - the interface is a supported firmware service and cannot be disabled. Reduce blast radius by restricting which host-side tools can issue SMIs and by not granting untrusted tenants root on bare metal running unpatched firmware. NCC Group published the underlying research, which is worth reading before assessing your exposure.
References
Related entries
- Dell PowerEdge Server BIOS (privilege management): An improper privilege-management flaw in PowerEdge BIOSCVE-2023-32460 · Dell PowerEdge Server BIOS (privilege management)High
- Supermicro BMC web interface CGI endpoints on X11 and M11 based boards with BMC firmware before 3.17.02CVE-2023-33412 · Supermicro BMC web interface CGI endpoints on X11 and M11 based boards with BMC firmware before 3.17.02High
- Supermicro BMC configuration functionality on X11 and M11 based boards through firmware 3.17.02: Arbitrary commandCVE-2023-33413 · Supermicro BMC configuration functionality on X11 and M11 based boards through firmware 3.17.02High
- EDK II NetworkPkg (DHCPv6 DNS Servers option handling): A crafted DNS Servers option inside a DHCPv6 AdvertiseCVE-2023-45234 · EDK II NetworkPkg (DHCPv6 DNS Servers option handling)High
- EDK II NetworkPkg (DHCPv6 proxy Advertise, Server ID option): Buffer overflow in the proxy-DHCPv6 pathCVE-2023-45235 · EDK II NetworkPkg (DHCPv6 proxy Advertise, Server ID option)High
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en/tc): Hardware flow-offload rules are programmed from a staleCVE-2023-54262 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en/tc)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.