Database/Firmware, BMC & network fabric
Supermicro X11SSL-CF hardware revision 1.01, BMC firmware v1.63: A local low-privilege actor gains write access
Impact
A local low-privilege actor gains write access to something they should not be able to modify. What makes this worth tracking despite the modest score is where it sits: the VRM advisory track covers voltage regulator firmware, and write access to power-delivery firmware on a server is a physical-damage and availability primitive, not just an integrity one. On dense GPU nodes where the VRMs are already running near their limits, an attacker able to tamper with regulator configuration has a plausible path to hardware damage or node-level denial of service that no software remediation reverses. Insecure permissions, disclosed under Supermicro's VRM (voltage regulator module) advisory track rather than the BMC track.
Who can reach it
Local access to the node with low privilege - a user account on the host, not necessarily root. The permissions problem is on the node itself rather than across the management network.
What to do
Firmware update per Supermicro's January 2023 VRM advisory. VRM firmware is updated separately from BIOS and BMC on Supermicro platforms, which is the operational trap here: an operator who believes they have a fully patched node because BIOS and BMC are current may still be running vulnerable regulator firmware. Add VRM firmware to whatever inventory you use to track BIOS and BMC versions, because most fleet tooling does not enumerate it by default.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.