Database/Firmware, BMC & network fabric
Supermicro X12DPG-QR BIOS 1.4b: Control-flow hijack inside platform firmware, driven by an NVRAM variable
Impact
Control-flow hijack inside platform firmware, driven by an NVRAM variable that host-side privileged code can set. The attacker moves from OS root into firmware-privileged execution and can establish a UEFI-resident implant. On a X12DPG-QR - a dual-socket GPU platform board - the payoff is a persistent presence on an accelerator node that reimaging does not touch and that the operator has no host-side way to detect. A buffer overflow reachable by manipulating the SmcSecurityEraseSetupVar UEFI variable, i.e. an NVRAM variable that firmware trusts without validating its contents.
Who can reach it
Local, host-side privileged code that can write UEFI variables. On Linux that means root with access to efivarfs. This is the standard escalation available to anyone who has rented the metal or otherwise obtained host root.
What to do
BIOS flash to a fixed image per Supermicro's August 2023 BIOS advisory, delivered as the X12DPG-QR BIOS package. Requires a host reboot. A partial hardening step that costs nothing: restrict or remove write access to efivarfs in tenant-facing bare-metal images, which raises the bar for any NVRAM-variable attack, not just this one. It does not substitute for the flash, because a tenant with root can usually reach the variable store another way.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.