Database/Firmware, BMC & network fabric

UEFI firmware SMM modules in Intel reference platform firmware (SMM handler, FlashUcAcmSmm, ImcErrorHandler, WheaERST
Impact
Improper input validation in SMM modules that Intel ships as reference code and that OEMs build into their server BIOS. SMM is the most privileged execution mode on the platform - above the hypervisor - so an escalation here gives an attacker control of the platform beneath every isolation boundary the fleet relies on, including access to the SPI flash write path. The result is a firmware implant that survives reimage and crosses tenant handoff, and that can neutralise measured boot from underneath. Because this is Intel reference code, the same defect propagates identically across every OEM that consumed that code drop, so exposure is fleet-wide across mixed vendors rather than isolated to one supplier.
Who can reach it
A privileged local user on the host - local root or an existing kernel foothold triggering the SMI. On bare-metal GPU nodes, that is the tenant.
What to do
BIOS update from each OEM once they pick up Intel's fixed reference code - Dell, HPE, Supermicro, Lenovo, Gigabyte, Quanta and Wiwynn all ship independently, and for reference-code advisories the lag from Intel's disclosure to a shipped server BIOS routinely runs one to two quarters, longer for ODM whitebox. Requires host reboot and job drain. Track this by OEM BIOS version rather than by CVE, because OEM release notes often reference only their own advisory ID. No runtime mitigation exists for SMM defects.
References
Related entries
- Arista CVX: authenticated Redis session escalates to root on every server in the CVX clusterCVE-2025-5088 · Arista CloudVision eXchange (CVX) Redis serviceHigh
- AMI AptioV UEFI firmware: incomplete input validation lets a privileged local user execute code in firmware contextCVE-2026-33197 · AMI AptioV UEFI firmware (BIOS input validation)High
- Linux kernel mlx5_core eswitch / vport (SR-IOV): Mlx5_core sizes a firmware command buffer from the physical function'sCVE-2026-53230 · Linux kernel mlx5_core eswitch / vport (SR-IOV)High
- Arista EOS gNMI: crafted request from an authenticated client executes code as rootCVE-2026-73464 · Arista EOS (gNMI - gRPC Network Management Interface)High
- Cisco FXOS / NX-OS AAA: AAA implementation flaw enabling remote DoS via brute-force login attempts against the switchCVE-2017-3883 · Cisco FXOS / NX-OS AAAHigh
- Cisco NX-OS PTP feature (Nexus 5500/5600/6000): An unauthenticated remote attacker takes down a Nexus switch throughCVE-2018-0378 · Cisco NX-OS PTP feature (Nexus 5500/5600/6000)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.