GPU VulnDB

Database/Firmware, BMC & network fabric

Leased colocation facility infrastructure (power, cooling, access control) as a class: Most GPU operators lease space

NCVD-2026-035-leased-colocation-facility-infraFirmware, BMC & network fabricfacility VLAN ownership gapcolo landlord equipmentcurated

Impact

Most GPU operators lease space rather than own buildings, which means the UPS, switchgear, PDU upstream feeds, CRAH units and access control that determine whether their GPUs stay powered and cooled are the landlord's equipment, on the landlord's network, patched on the landlord's schedule - which is frequently never, because facility gear is treated as a fixed asset rather than as software. Every CVE in this file is therefore, for many operators, a vulnerability they carry the consequences of and have no authority to fix. An availability event here takes out a hall regardless of how well the compute plane is run.

Who can reach it

Whoever can reach the landlord's facility network - which typically includes the landlord's own vendors, remote-monitoring contractors, and any building-management remote access path the operator has never seen.

What to do

Contractual, not technical. Require in the colocation agreement: a current inventory of facility control equipment with firmware versions, evidence of a patch cadence, segmentation of the facility network from any operator-reachable network, notification of remote-access paths granted to third parties, and the right to audit. Then verify rather than trust. Where a landlord will not commit, price the risk into the site decision - this belongs in site selection, not in the security backlog.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.