Database/Firmware, BMC & network fabric
Intel Server Platform Services (SPS) firmware 4.0 kernel
Impact
Multiple buffer overflows and privilege escalations in the SPS kernel let an unauthorized process on the host run code inside the SPS firmware itself. SPS is the management-engine flavour that ships on Xeon server chipsets - it owns Node Manager power capping, PECI thermal telemetry, and the sideband path to the BMC. Code execution there is below-the-OS persistence that survives a tenant reimage and is invisible to any host-based agent, and because SPS drives power and thermal management it carries direct physical consequence: an attacker in SPS can lie about power/thermal telemetry to the BMC and DCIM, or manipulate power limits on a node.
Who can reach it
A local unprivileged-to-privileged process on the host reaching the SPS firmware through the HECI/MEI interface. No network exposure required, no physical access. On a bare-metal GPU node this is reachable by any tenant who has root.
What to do
SPS firmware flash, delivered only as an OEM BIOS/firmware bundle - Dell (iDRAC-driven DUP), HPE (SPP), Supermicro, Lenovo, Gigabyte, Quanta each ship their own, and for SA-00086 the OEM releases trailed Intel's November 2017 advisory by one to six months on server boards. Needs a full host reboot, so it drains every running training job on the node. There is no host-side mitigation: SPS cannot be disabled on a server chipset the way AMT can be unprovisioned. Verify the post-flash SPS version out of band via the BMC, not from the host.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.