Database/Firmware, BMC & network fabric
AMD Secure Processor bootloader - SPIROM upgrade path: An attacker who can drive the SPIROM upgrade path can pass
Impact
An attacker who can drive the SPIROM upgrade path can pass unsanitised parameters to the ASP bootloader and overwrite memory, reaching arbitrary code execution in the secure processor. This is the classic firmware-update-as-attack-surface problem: the mechanism you use to patch the platform is itself the way in.
Who can reach it
Local, requires access to the SPI ROM upgrade mechanism - typically root plus flash write, or a compromised BMC that can drive host SPI.
What to do
Fixed in AMD reference firmware (AGESA / SEV firmware) and delivered to you only as an OEM SBIOS/BIOS package - Dell, HPE, Supermicro, Lenovo, Gigabyte and the ODMs each rebuild and requalify AMD's AGESA drop before it ships. **Expect months, not weeks**: AMD publishes the bulletin, the OEM ships BIOS somewhere between one and six months later, and for platforms past their support window it may never arrive at all. Applying it is a full node power cycle with the host drained - not a driver reload, not a live patch. Track it as a firmware campaign per server SKU, not per kernel version, and verify afterwards by reading back the SMU/PSP firmware version rather than trusting the BIOS revision string. Worth pairing with BMC hardening: on most server designs the BMC can write host SPI, so a BMC compromise reaches this directly. Restrict who can invoke firmware updates and require signed update packages end to end.
References
Related entries
- Supermicro BMC SMASH-CLP shell on MBD-X13SEDW-F: Full control of the instruction pointer inside the BMC's firmware OSCVE-2025-7623 · Supermicro BMC SMASH-CLP shell on MBD-X13SEDW-FMedium
- AMD Platform Security Processor - SEV key derivation (PSP firmware <= 0.17 build 11): The SEV implementation in PSPCVE-2019-9836 · AMD Platform Security Processor - SEV key derivation (PSP firmware <= 0.17 build 11)Medium
- HPE iLO 4 / iLO 5 (unauthenticated information disclosure): An unauthenticated remote request pulls back the serverCVE-2020-7202 · HPE iLO 4 / iLO 5 (unauthenticated information disclosure)Medium
- APC/Schneider Electric UPS, PDU, and cooling products using NMC2/NMC3 (Smart-UPS, Symmetra, Galaxy, rack PDUs, InRowCVE-2021-22815 · APC/Schneider Electric UPS, PDU, and cooling products using NMC2/NMC3Medium
- AMI MegaRAC SPx 12 / SPx 13 (BMC login): The login flow answers differently for real and fake usernames, soCVE-2021-45925 · AMI MegaRAC SPx 12 / SPx 13 (BMC login)Medium
- AMI MegaRAC: Weak MD5 password hashing for BMC accountsCVE-2022-40258 · AMI MegaRACMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.