GPU VulnDB

Database/Firmware, BMC & network fabric

Intel CSME 12.0.0-12.0.34: A buffer overflow in a CSME subsystem reachable over the network by an unauthenticated

CVE-2019-0153Firmware, BMC & network fabriccurated

Impact

A buffer overflow in a CSME subsystem reachable over the network by an unauthenticated attacker, giving privilege escalation on the management engine. CSME sits below the OS with its own network stack, so a network-reachable overflow there is control of the platform outside anything the host can observe or defend.

Who can reach it

Unauthenticated network access to the affected CSME service. Whether that is reachable depends entirely on how isolated your management network is.

What to do

Fixed in Intel CSME/SPS firmware, which reaches you as an OEM BIOS or firmware package - not as a microcode or OS update. That means: wait for your server vendor to ship it, drain the node, flash, and reboot. OEM availability is the long pole and routinely lags the Intel advisory by one or more quarters on server platforms. Track it per platform SKU, because vendors ship these unevenly across their own product lines. Until firmware lands, isolate the management network - this class of bug is unreachable if the management plane is not routable from anywhere a tenant can be.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.