GPU VulnDB

Database/Firmware, BMC & network fabric

AMI AptioV UEFI BIOS (SPI flash access control): Improper access control in the BIOS that lets a local attacker make

CVE-2024-2315Firmware, BMC & network fabricAMI-SA-2024004curated

Impact

Improper access control in the BIOS that lets a local attacker make unexpected SPI flash modifications and launch a BIOS bootkit. This is the direct route to firmware persistence: write the flash, own every subsequent boot, and become invisible to the OS and to every agent running in it. AMI also calls out an availability impact - a bad write bricks the board, which on a GPU node means an RMA and weeks of lost capacity rather than a reboot.

Who can reach it

Local access with low privileges, no user interaction. Code on the host OS is enough; it does not require root by AMI's scoring. That makes it one of the cheaper firmware-persistence paths in this cluster for an attacker who has landed anywhere on the node.

What to do

BIOS update to BKC_5.37 or later - firmware flash plus a host reboot, per node, gated on your server vendor's rebase. Alongside the update, verify that the platform's flash write protections are actually enabled in your BIOS configuration (flash descriptor lock, BIOS write-protect, boot guard where the platform supports it) - operators routinely find these left open by an OEM's default profile, and that config check costs one reboot rather than a flash campaign.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.