Database/Firmware, BMC & network fabric
Broadcom NetXtreme-E network adapter firmware: A high-severity flaw in the firmware of Broadcom NetXtreme-E adapters
Impact
A high-severity flaw in the firmware of Broadcom NetXtreme-E adapters (found in firmware 231.1.162.1 and reported through Positive Technologies' responsible-disclosure process). NetXtreme-E is Broadcom's mainstream datacenter NIC line and the base for the Thor generation used in AI server designs. Adapter-firmware bugs matter more than their CVSS suggests: NIC firmware runs below the hypervisor and below the host OS, it persists across reinstall, and on many server designs the NIC also carries the NC-SI sideband to the BMC — so a compromised NIC is a candidate pivot into out-of-band management.
Who can reach it
Reachable through the adapter's firmware interfaces. Treat any party that can drive the NIC — a host-privileged tenant on bare metal, or network-side input depending on the affected path — as in scope until the vendor detail is public.
What to do
Flash NetXtreme-E adapter firmware to the fixed release from Broadcom (or via your server OEM's firmware bundle). NIC firmware flash plus a cold power cycle, per node. On a GPU fleet, roll it into the same drain window you use for BMC and BIOS updates — doing NIC firmware as its own campaign is how it ends up never happening.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.