Database/Firmware, BMC & network fabric
Dell PowerEdge Server BIOS (AMD platforms, TOCTOU race): A time-of-check/time-of-use race in BIOS gives
CVSS 5.3CVE-2024-0171Firmware, BMC & network fabriccurated
Impact
A time-of-check/time-of-use race in BIOS gives a low-privileged local attacker access to resources outside its authorization. Relevant to the AMD EPYC-based GPU platforms.
Who can reach it
Local low-privilege user on an AMD-based PowerEdge.
What to do
Flash the fixed PowerEdge BIOS. A BIOS update is a cold reboot per node and cannot be done live - on a GPU fleet that means draining jobs and taking the box out of the scheduler, so batch it with other firmware work rather than doing a standalone pass.
References
Related entries
- Arista EOS (MACsec with egress ACLs): On interfaces with both MACsec and egress ACLs configured, the egress ACL is notCVE-2024-27891 · Arista EOS (MACsec with egress ACLs)Medium
- Intel UEFI firmware (OutOfBandXML module): Improper initialisation in the OutOfBandXML UEFI module allows a privilegedCVE-2024-31157 · Intel UEFI firmware (OutOfBandXML module)Medium
- Dell PowerEdge 14G Intel BIOS (improper input validation): A high-privileged local attacker extracts informationCVE-2024-38303 · Dell PowerEdge 14G Intel BIOS (improper input validation)Medium
- Insyde InsydeH2O (IHISI function 0x49, UEFI variable factory reset): IHISI function 0x49 restores certain UEFICVE-2024-39707 · Insyde InsydeH2O (IHISI function 0x49, UEFI variable factory reset)Medium
- GRUB2 (HFS+ filesystem parser): A reference count can be decremented twice, producing a use-after-freeCVE-2024-45783 · GRUB2 (HFS+ filesystem parser)Medium
- AMD CPU - stale TLB entries in SEV-SNP guests: A silicon bug lets a local admin-privileged attacker run an SEV-SNPCVE-2025-29934 · AMD CPU - stale TLB entries in SEV-SNP guestsMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.