Database/Firmware, BMC & network fabric

AMI AptioV BIOS (improper input validation, SMM): A local attacker overwrites arbitrary memory and executes code at SMM
Impact
A local attacker overwrites arbitrary memory and executes code at SMM level with scope change. AptioV is the UEFI firmware under a very large fraction of x86 servers, so this is a cross-OEM firmware issue.
Who can reach it
Local low-privilege access to the server.
What to do
AMI ships the fix to OEMs, not to you - obtain the updated BIOS from your board/server vendor (Supermicro, Gigabyte, ASRock Rack, Quanta, Tyan etc.) and flash it. Expect a lag of weeks to months between the AMI advisory and an OEM image for your exact SKU, and expect some SKUs never to get one. Cold reboot per node.
References
Related entries
- Dell SmartFabric OS10 (execution with unnecessary privileges): A low-privileged attacker escalates through an OS10CVE-2024-48013 · Dell SmartFabric OS10 (execution with unnecessary privileges)High
- Dell SmartFabric OS10 (default password): A default password in SmartFabric OS10 across 10.5.4.x through 10.6.0.xCVE-2024-49559 · Dell SmartFabric OS10 (default password)High
- Linux kernel mlx5_ib (InfiniBand/RoCE completion queue polling): mlx5_poll_one() compares the firmware's QP numberCVE-2025-22086 · Linux kernel mlx5_ib (InfiniBand/RoCE completion queue polling)High
- Dell SmartFabric OS10 (command injection): Second command-injection path in the same OS10 advisory, givingCVE-2025-46427 · Dell SmartFabric OS10 (command injection)High
- Dell SmartFabric OS10 (command injection): A low-privileged remote attacker executes code on the switch OSCVE-2025-46428 · Dell SmartFabric OS10 (command injection)High
- ATEN eco DC (DCIM/environmental management platform): The web interface doesn't check a user's assigned roleCVE-2025-6685 · ATEN eco DC (DCIM/environmental management platform)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.