GPU VulnDB

Database/Control plane, storage & DevOps

Intel SPS (HECI subsystem compartmentalisation): Insufficient compartmentalisation in the HECI interface

CVE-2021-0060Control plane, storage & DevOpscurated

Impact

Insufficient compartmentalisation in the HECI interface - the host-to-management-engine channel - on Server Platform Services firmware. HECI is the door between the OS and the management engine, so weak compartmentalisation there means host-side code reaches further into the engine than it should.

Who can reach it

Local access on the host with the ability to talk to the HECI device.

What to do

Fixed in Intel CSME/SPS firmware, which reaches you as an OEM BIOS or firmware package - not as a microcode or OS update. That means: wait for your server vendor to ship it, drain the node, flash, and reboot. OEM availability is the long pole and routinely lags the Intel advisory by one or more quarters on server platforms. Track it per platform SKU, because vendors ship these unevenly across their own product lines.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.