Database/Firmware, BMC & network fabric

HPE SAS SSDs EK0800JVYPN, EO1600JVYPP, MK0800JVYPQ, MO1600JVYPR (800GB/1.6TB 12G SAS) with firmware prior to HPD7
Impact
PHYSICAL / FLEET-WIDE AVAILABILITY EVENT, and the second one in four months - which is the real finding. At exactly 40,000 power-on hours, roughly 4.6 years, these drives fail permanently and HPE states that neither the data nor the drive can be recovered. Same correlated-failure property as the 32,768-hour bug: co-installed drives die together, so RAID fault tolerance is exceeded and the array goes with them. Affects HPE ProLiant, Synergy, Apollo 4200 and StoreEasy platforms - general-purpose server and storage hardware of exactly the kind that gets repurposed into GPU and AI build-outs. That two independent counter-overflow bombs surfaced in one vendor's SAS SSD line within months tells you this is a recurring firmware-engineering failure mode, not a freak event.
Who can reach it
No attacker. Elapsed powered-on hours, hitting every drive from the same deployment batch at the same moment. HPE projected the first failures would begin around October 2020.
What to do
Flash to HPD7 or later before the threshold; HPE released it on 20 March 2020 with VMware ESXi, Windows and Linux packages. Post-failure there is no recovery - restore from backup. As with the 32,768-hour bug the first action is a fleet-wide power-on-hours audit (HPE Smart Storage Administrator or smartctl attribute 9) to find which drives are closest to the line, then a staggered rolling drain-and-flash sequenced by hours remaining rather than by rack. Make the standing controls permanent rather than treating this as a one-off: monitor power-on hours as a first-class fleet metric with alerting well ahead of any known threshold, subscribe to drive-vendor firmware bulletins as an operational feed, and deliberately mix procurement batches and vendors across redundancy groups so no single firmware defect can reach every member of an array simultaneously.
References
Related entries
- AMD Platform Secure Boot (PSB) OEM key fusing on EPYC server boards: PSB is the fuse-backed root of trust that makesNCVD-2021-001-amd-platform-secure-boot-psb-oem · AMD Platform Secure Boot (PSB) OEM key fusing on EPYC server boardsUnscored
- Discrete TPM (LPC / SPI bus, unencrypted sessions): A discrete TPM talks to the CPU over LPC or SPI in the clear unlessNCVD-2021-002-discrete-tpm-lpc-spi-bus-unencry · Discrete TPM (LPC / SPI bus, unencrypted sessions)Unscored
- Intel CPUs with SGX, attacked over the SVID serial bus between the voltage regulator and the CPU package: Re-runsNCVD-2021-005-intel-cpus-with-sgx-attacked-ove · Intel CPUs with SGX, attacked over the SVID serial bus between the voltage regulator and the CPU packageUnscored
- DDR4 chips from all three major DRAM manufacturers; worsens as process nodes shrink: A different read-disturbanceNCVD-2023-001-ddr4-chips-from-all-three-major · DDR4 chips from all three major DRAM manufacturers; worsens as process nodes shrinkUnscored
- Gigabyte UEFI firmware (OEM update-dropper in firmware): Gigabyte firmware shipped a UEFI module that writes a WindowsNCVD-2023-001-gigabyte-uefi-firmware-oem-updat · Gigabyte UEFI firmware (OEM update-dropper in firmware)Unscored
- Intel processors with Linear Address Masking (LAM): SLAM: Linear Address Masking, a feature intended to let softwareNCVD-2023-001-intel-processors-with-linear-add · Intel processors with Linear Address Masking (LAM)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.