Database/Firmware, BMC & network fabric
Intel 4th Gen Xeon on-chip debug and test interface (with SGX or TDX): The on-chip debug and test interface has
Impact
The on-chip debug and test interface has improper access control on 4th-generation Xeon when SGX or TDX is enabled, giving a privileged user escalation. Debug interfaces reaching into a TEE is the single worst shape for a confidential-compute claim, because it bypasses the architectural boundary entirely rather than working around it.
Who can reach it
Privileged local access on the host.
What to do
Microcode/platform firmware update plus TCB recovery. Where the fix lands in microcode it can be late-loaded at boot; where it lands in BIOS, expect the OEM lag. Re-attest afterwards.
References
Related entries
- AMI MegaRAC SPx (SPX REST API): Arbitrary read and write into the memory of the BMC's IPMI server process via the SPXCVE-2023-34341 · AMI MegaRAC SPx (SPX REST API)High
- AMI MegaRAC SPx (SPX REST API): Shell command injection through the BMC's REST APICVE-2023-34343 · AMI MegaRAC SPx (SPX REST API)High
- Supermicro BMC (IPMI web interface, command injection): Command injection that turns a BMC administrator accountCVE-2023-40289 · Supermicro BMC (IPMI web interface, command injection)High
- Dell PowerEdge Server BIOS (SMM communication buffer): The BIOS fails to properly validate the SMM communicationCVE-2024-0161 · Dell PowerEdge Server BIOS (SMM communication buffer)High
- Supermicro BMC firmware validation (MBD-X12DPG-OA6): Root-of-Trust bypassCVE-2024-10237 · Supermicro BMC firmware validation (MBD-X12DPG-OA6)High
- Supermicro BMC firmware image verification routine on MBD-X12DPG-OA6: A crafted update image smashes the stackCVE-2024-10238 · Supermicro BMC firmware image verification routine on MBD-X12DPG-OA6High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.