Database/Firmware, BMC & network fabric

AMI AptioV UEFI BIOS: A race condition in the BIOS that a skilled local attacker can drive to resource exhaustion
Impact
A race condition in the BIOS that a skilled local attacker can drive to resource exhaustion, with AMI rating full confidentiality, integrity and availability impact and a subsequent-system impact as well. The operator-facing outcome is a node that fails to complete firmware operations or wedges in early boot - and given the CIA rating AMI assigns, a successfully-won race is a path to firmware-level compromise rather than just a hang. Winning a race in firmware is exactly the kind of bug that is unreliable in a lab and reliable at fleet scale, where an attacker gets thousands of boot attempts.
Who can reach it
Local access with high privileges and some user interaction, and the attack requires specific conditions to be present - AMI's CVSS v4 vector marks attack requirements as present, meaning the attacker needs the machine in a particular state. Realistically: root on the host plus the ability to trigger a reboot or a firmware operation, which any tenant of a bare-metal node has.
What to do
BIOS update to AptioV_5.040 or later - firmware flash plus a host reboot per node, gated on your server vendor rebasing the AMI BKC for your SKU. No config-only workaround. Because the trigger involves reboots and firmware operations, one thing you can do without patching is restrict who can initiate BIOS updates and firmware operations out-of-band, and log every one of them.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.