GPU VulnDB

Database/Firmware, BMC & network fabric

Supermicro X12DPG-QR BIOS 1.4b: Control-flow hijack inside platform firmware, driven by an NVRAM variable

CVE-2023-34853Firmware, BMC & network fabriccurated

Impact

Control-flow hijack inside platform firmware, driven by an NVRAM variable that host-side privileged code can set. The attacker moves from OS root into firmware-privileged execution and can establish a UEFI-resident implant. On a X12DPG-QR - a dual-socket GPU platform board - the payoff is a persistent presence on an accelerator node that reimaging does not touch and that the operator has no host-side way to detect. A buffer overflow reachable by manipulating the SmcSecurityEraseSetupVar UEFI variable, i.e. an NVRAM variable that firmware trusts without validating its contents.

Who can reach it

Local, host-side privileged code that can write UEFI variables. On Linux that means root with access to efivarfs. This is the standard escalation available to anyone who has rented the metal or otherwise obtained host root.

What to do

BIOS flash to a fixed image per Supermicro's August 2023 BIOS advisory, delivered as the X12DPG-QR BIOS package. Requires a host reboot. A partial hardening step that costs nothing: restrict or remove write access to efivarfs in tenant-facing bare-metal images, which raises the bar for any NVRAM-variable attack, not just this one. It does not substitute for the flash, because a tenant with root can usually reach the variable store another way.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.