Database/Firmware, BMC & network fabric

Phoenix SecureCore Technology 4 (SMI handler, improper access control): An SMI handler with missing access control lets
Impact
An SMI handler with missing access control lets an attacker modify the SPI flash. That is the direct route to a permanent firmware implant: rewrite the boot flash and the compromise survives OS reinstall, disk replacement and node reimaging between tenants, while sitting below Secure Boot and below anything attestation can honestly measure. Highest-scored Phoenix advisory in this set.
Who can reach it
Local attacker on the host with the ability to invoke the SMI handler - in practice admin/root, or a tenant with kernel access on bare metal.
What to do
OEM BIOS update on the fixed SecureCore Technology 4 build (affected from 4.3.0.0). Firmware flash, one reboot per node. No config workaround for the handler itself, but this is the case where platform SPI protections earn their keep: confirm BIOS Lock Enable, SMM BIOS Write Protect and protected range registers are actually set on your platform - many OEM defaults leave at least one of them off, and a properly locked flash blunts the primitive even on unpatched firmware.
References
Related entries
- AMD Secure Processor - XGMI Trusted Agent (type confusion): Type confusion in the ASP's XGMI Trusted Agent means aCVE-2023-31323 · AMD Secure Processor - XGMI Trusted Agent (type confusion)High
- Dell SmartFabric OS10 (hard-coded password): A hard-coded password in OS10 10.5.6.x gives an unauthenticated attackerCVE-2024-48831 · Dell SmartFabric OS10 (hard-coded password)High
- Supermicro BMC firmware update signature/validation logic on the X13SEM-F motherboard family: The operator losesCVE-2025-12007 · Supermicro BMC firmware update signature/validation logic on the X13SEM-F motherboard familyHigh
- Junos OS: missing authentication in command processing gives a privileged local user root on line cardsCVE-2025-30650 · Juniper Junos OS (command processing on Linux-based line cards: MPC7-11, LC2101/480/9600, MX304, MX-SPC3, PTX FPC3)High
- IBM Power Systems Firmware: HMC-authenticated attacker executes code on the service processorCVE-2026-16832 · IBM Power Systems Firmware (FSP management network protocol)High
- Linux kernel (drivers/infiniband/core): IWARP port-mapper netlink attributes were accepted as plain strings with noCVE-2026-63860 · Linux kernel (drivers/infiniband/core)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.