Database/Firmware, BMC & network fabric
Supermicro BIOS SMM callout (X11DPH-T / X11DPH-Tq): Execution in System Management Mode, the most privileged execution
Impact
Execution in System Management Mode, the most privileged execution context on the machine - above the hypervisor, invisible to the OS, and able to write the platform's own firmware. An SMM implant is the deepest persistent foothold available on an x86 node: it survives OS reinstall, disk replacement, and hypervisor redeployment, and no host-based tooling can enumerate it. For a bare-metal operator this is the finding that breaks the tenant handoff guarantee outright, because you cannot prove a returned node is clean. And X11DPH-i before version 4.4 - SMM code calling out to memory the attacker controls, which is the classic route from ring 0 into ring -2.
Who can reach it
Local, host-side, high privilege - root on the node's OS, triggering the SMI that reaches the vulnerable callout. Attack complexity is rated high, so it is a targeted attack rather than an opportunistic one, but a bare-metal tenant has unlimited time and full access to attempt it.
What to do
BIOS flash to 4.4 or later from Supermicro's July 2024 BIOS advisory, per board. Same image covers the arbitrary-write issues on the neighbouring X11DPH SKUs, so batch them. There is no configuration change that mitigates an SMM callout. If you rent bare metal on these boards, the additional operational control worth adding is a firmware measurement taken at node return and compared against a known-good baseline, since a patched BIOS does not tell you whether the node was implanted before you patched it.
References
Related entries
- Dell SmartFabric OS10 (uncontrolled resource consumption): A remote unauthenticated host can exhaust resources on anCVE-2024-37125 · Dell SmartFabric OS10 (uncontrolled resource consumption)High
- Sunbird DCIM dcTrack v9.1.2 - ticket location RBAC: Incorrect access control lets an attacker create or update ticketsCVE-2024-37775 · Sunbird DCIM dcTrack v9.1.2 - ticket location RBACHigh
- Dell SmartFabric OS10 (command injection): Command injection in SmartFabric OS10 10.5.5.4-10.5.5.10 and 10.5.6.xCVE-2024-38486 · Dell SmartFabric OS10 (command injection)High
- Linux kernel - RDMA/rxe unreliable datagram responder, drivers/infiniband/sw/rxe/rxe_resp.c: The IB architecture says aCVE-2024-40992 · Linux kernel - RDMA/rxe unreliable datagram responder, drivers/infiniband/sw/rxe/rxe_resp.cHigh
- Linux kernel NVMe-oF RDMA target (nvmet, uninitialised completion-entry result field): This is a straight kernel-stackCVE-2024-41079 · Linux kernel NVMe-oF RDMA target (nvmet, uninitialised completion-entry result field)High
- Linux kernel InfiniBand core (ib_umad): ib_umad kept received management datagrams on an unbounded listCVE-2024-42145 · Linux kernel InfiniBand core (ib_umad)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.