Database/Firmware, BMC & network fabric
Leased colocation facility infrastructure (power, cooling, access control) as a class: PHYSICAL. Most GPU operators
Impact
PHYSICAL. Most GPU operators lease space rather than own buildings, which means the UPS, switchgear, PDU upstream feeds, CRAH units and access control that determine whether their GPUs stay powered and cooled are the landlord's equipment, on the landlord's network, patched on the landlord's schedule - which is frequently never, because facility gear is treated as a fixed asset rather than as software. Every CVE in this file is therefore, for many operators, a vulnerability they carry the consequences of and have no authority to fix. An availability event here takes out a hall regardless of how well the compute plane is run.
Who can reach it
Whoever can reach the landlord's facility network - which typically includes the landlord's own vendors, remote-monitoring contractors, and any building-management remote access path the operator has never seen.
What to do
Contractual, not technical. Require in the colocation agreement: a current inventory of facility control equipment with firmware versions, evidence of a patch cadence, segmentation of the facility network from any operator-reachable network, notification of remote-access paths granted to third parties, and the right to audit. Then verify rather than trust. Where a landlord will not commit, price the risk into the site decision - this belongs in site selection, not in the security backlog.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.