GPU VulnDB

Database/Firmware, BMC & network fabric

Intel Server Platform Services (SPS) firmware 4.0 kernel

CVE-2017-5709Firmware, BMC & network fabricINTEL-SA-00086CVE-2017-5706CVE-2017-5705curated

Impact

Multiple buffer overflows and privilege escalations in the SPS kernel let an unauthorized process on the host run code inside the SPS firmware itself. SPS is the management-engine flavour that ships on Xeon server chipsets - it owns Node Manager power capping, PECI thermal telemetry, and the sideband path to the BMC. Code execution there is below-the-OS persistence that survives a tenant reimage and is invisible to any host-based agent, and because SPS drives power and thermal management it carries direct physical consequence: an attacker in SPS can lie about power/thermal telemetry to the BMC and DCIM, or manipulate power limits on a node.

Who can reach it

A local unprivileged-to-privileged process on the host reaching the SPS firmware through the HECI/MEI interface. No network exposure required, no physical access. On a bare-metal GPU node this is reachable by any tenant who has root.

What to do

SPS firmware flash, delivered only as an OEM BIOS/firmware bundle - Dell (iDRAC-driven DUP), HPE (SPP), Supermicro, Lenovo, Gigabyte, Quanta each ship their own, and for SA-00086 the OEM releases trailed Intel's November 2017 advisory by one to six months on server boards. Needs a full host reboot, so it drains every running training job on the node. There is no host-side mitigation: SPS cannot be disabled on a server chipset the way AMT can be unprovisioned. Verify the post-flash SPS version out of band via the BMC, not from the host.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.