Database/Firmware, BMC & network fabric

Intel UEFI firmware (OutOfBandXML module): Improper initialisation in the OutOfBandXML UEFI module allows a privileged
Impact
Improper initialisation in the OutOfBandXML UEFI module allows a privileged user to disclose information from firmware. The out-of-band XML path is part of remote platform configuration, so it is reachable in the management workflows operators actually automate.
Who can reach it
Privileged local access on the host.
What to do
Fixed in platform BIOS/UEFI firmware. That means an OEM release, a per-node drain, a flash and a cold reboot - and OEM availability commonly lags the Intel advisory by quarters on server boards. There is no microcode or OS-level shortcut for this class; budget it as a fleet-wide maintenance campaign, not a patch.
References
Related entries
- Dell PowerEdge 14G Intel BIOS (improper input validation): A high-privileged local attacker extracts informationCVE-2024-38303 · Dell PowerEdge 14G Intel BIOS (improper input validation)Medium
- Insyde InsydeH2O (IHISI function 0x49, UEFI variable factory reset): IHISI function 0x49 restores certain UEFICVE-2024-39707 · Insyde InsydeH2O (IHISI function 0x49, UEFI variable factory reset)Medium
- GRUB2 (HFS+ filesystem parser): A reference count can be decremented twice, producing a use-after-freeCVE-2024-45783 · GRUB2 (HFS+ filesystem parser)Medium
- AMD CPU - stale TLB entries in SEV-SNP guests: A silicon bug lets a local admin-privileged attacker run an SEV-SNPCVE-2025-29934 · AMD CPU - stale TLB entries in SEV-SNP guestsMedium
- Dell iDRAC Service Module (iSM, incorrect permissions): Incorrect permission assignment on a critical resource letsCVE-2025-38742 · Dell iDRAC Service Module (iSM, incorrect permissions)Medium
- AMD CPU microcode - bound check: An improper bound check inside AMD CPU microcode lets a malicious **guest** write intoCVE-2025-52534 · AMD CPU microcode - bound checkMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.