Database/Firmware, BMC & network fabric

Insyde InsydeH2O (IHISI function 0x49, UEFI variable factory reset): IHISI function 0x49 restores certain UEFI
Impact
IHISI function 0x49 restores certain UEFI variables to factory defaults with no authentication by default. That is a rollback primitive: an attacker resets security-relevant firmware settings that an operator had hardened - and on affected platforms can wind protections back to a weaker known state without needing to exploit anything. For a fleet where node hardening is applied once at provisioning and then assumed, this quietly undoes it, and nothing in the OS logs the change.
Who can reach it
Local attacker on the host OS able to invoke the IHISI interface. No authentication required on affected platforms.
What to do
OEM BIOS update carrying the Insyde fix, which makes the function require authentication. Firmware flash, reboot per node. Because the impact is settings rollback rather than code execution, the practical operator control is detection: baseline your BIOS settings at provisioning and re-verify them (via the OEM's redfish/BIOS-attribute API) on every node before it re-enters the tenant pool, rather than assuming a hardened node stays hardened.
References
Related entries
- GRUB2 (HFS+ filesystem parser): A reference count can be decremented twice, producing a use-after-freeCVE-2024-45783 · GRUB2 (HFS+ filesystem parser)Medium
- AMD CPU - stale TLB entries in SEV-SNP guests: A silicon bug lets a local admin-privileged attacker run an SEV-SNPCVE-2025-29934 · AMD CPU - stale TLB entries in SEV-SNP guestsMedium
- Dell iDRAC Service Module (iSM, incorrect permissions): Incorrect permission assignment on a critical resource letsCVE-2025-38742 · Dell iDRAC Service Module (iSM, incorrect permissions)Medium
- AMD CPU microcode - bound check: An improper bound check inside AMD CPU microcode lets a malicious **guest** write intoCVE-2025-52534 · AMD CPU microcode - bound checkMedium
- AMD Secure Processor - privilege check on write path: The ASP accepts an input value and performs a writeCVE-2025-54511 · AMD Secure Processor - privilege check on write pathMedium
- Arista EOS: crafted packet terminates the MACsec process and disrupts dataplane trafficCVE-2025-7048 · Arista EOS (MACsec process)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.