Database/Firmware, BMC & network fabric

Insyde InsydeH2O (SystemFirmwareManagementRuntimeDxe, GetImage method): The firmware reads a runtime UEFI variable
Impact
The firmware reads a runtime UEFI variable called GetImageProgress and then calls it as a function pointer. An attacker sets that variable from the OS to point at code they control and the firmware jumps to it during the DXE phase. This is a firmware-update-service driver, so the attacker ends up executing inside the machinery responsible for validating the next BIOS image - a direct route to a persistent, self-reinstalling firmware implant on a GPU node.
Who can reach it
Local admin/root on the host OS with UEFI variable write access, then a reboot or a firmware-management call that reaches GetImage.
What to do
OEM BIOS update carrying the fixed Insyde kernel (5.0-5.5 affected). Firmware flash, one reboot per node. No configuration mitigates it. Interim hardening: restrict OS-side UEFI variable writes, and where the platform supports it verify that capsule updates require a signed payload so an implant cannot re-flash itself through the same service.
References
Related entries
- AMI MegaRAC SPx 12 / SPx 13 (BMC): Untrusted pointer dereference in the BMC that a low-privileged actor can turnCVE-2023-34332 · AMI MegaRAC SPx 12 / SPx 13 (BMC)High
- AMI MegaRAC SPx (untrusted pointer dereference): Untrusted pointer dereference in the BMC allowing a local-networkCVE-2023-34333 · AMI MegaRAC SPx (untrusted pointer dereference)High
- Supermicro X12DPG-QR BIOS 1.4b: Control-flow hijack inside platform firmware, driven by an NVRAM variableCVE-2023-34853 · Supermicro X12DPG-QR BIOS 1.4bHigh
- Dell SmartFabric Storage Software (restricted shell in SSH): OS command injection escaping the restricted shell of theCVE-2023-43068 · Dell SmartFabric Storage Software (restricted shell in SSH)High
- GRUB2 (NTFS filesystem parser): Out-of-bounds write parsing a crafted NTFS volumeCVE-2023-4692 · GRUB2 (NTFS filesystem parser)High
- Phoenix SecureCore Technology 4 (boot splash screen image parsing): The firmware parses a user-supplied boot logo imageCVE-2023-5058 · Phoenix SecureCore Technology 4 (boot splash screen image parsing)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.