Database/Firmware, BMC & network fabric

AMI AptioV UEFI BIOS (SPI flash integrity verification): An actor with physical access can modify the SPI flash
Impact
An actor with physical access can modify the SPI flash without the modification being detected. The score is modest because it needs hands on the hardware, but the operator consequence is that your firmware integrity story has no floor: a node that passed through an untrusted physical environment can carry an undetectable implant. That matters concretely for GPU fleets in leased colo where remote hands are third-party staff, for hardware shipped internationally, for anything bought on the secondary market during a supply crunch, and for RMA units returning from a vendor depot.
Who can reach it
Physical access to the machine, no credentials needed. Anyone who can open the chassis and reach the SPI flash - datacenter remote-hands staff, shipping and logistics handling, a vendor's repair depot, or a hosting provider's own technicians.
What to do
BIOS update to BKC_5.37 or later - firmware flash plus reboot per node, vendor-rebase-gated. Because the threat model is physical rather than network, patching is only part of it: the process controls are what actually help. Take a firmware measurement baseline per node at commissioning, re-measure after any physical service event or RMA return, use chassis intrusion detection and seal logging, and treat any node that came back from third-party hands without a verified measurement as needing a reflash before it rejoins the pool.
References
Related entries
- shim (MZ/PE header parser): Out-of-bounds read parsing MZ binariesCVE-2023-40551 · shim (MZ/PE header parser)Medium
- Solidigm DC SSDs (D3-S4510/S4520/S4610/S4620, D5-P5316, D7-P5520/P5620, DC S4500/S4600)CVE-2024-47973 · Solidigm DC SSDs (D3-S4510/S4520/S4610/S4620, D5-P5316, D7-P5520/P5620, DC S4500/S4600) - over-provisioned NAND not…Medium
- Arm Neoverse V2 / V3 / V3AE, Cortex-X3 / X4 / X925, C1-seriesCVE-2024-7881 · Arm Neoverse V2 / V3 / V3AE, Cortex-X3 / X4 / X925, C1-series; mitigated in Trusted Firmware-A v2.2-v2.12 and LTS…Medium
- Junos Space: stored XSS in management UI pages lets an attacker run actions as a logged-in administratorCVE-2025-59990 · Juniper Junos Space (template creation and report generation pages)Medium
- NVIDIA UFM Enterprise: hard-coded key in session management allows information disclosure and privilege escalationCVE-2026-24166 · NVIDIA UFM Enterprise (session management, hard-coded cryptographic key)Medium
- IBM PowerVM PKS and virtual TPM: persistent key seeds produce a reduced-strength AES keyCVE-2026-4936 · IBM PowerVM Hypervisor Platform KeyStore (PKS) and virtual TPM, FW950 / FW1060 / FW1110Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.