BIOS firmware on Supermicro X11DPG-HGX2, X11PDG-QT, X11PDG-OT and X11PDG-SN before version 4.4: An arbitrary memory
Impact
An arbitrary memory write primitive inside platform firmware, on the boards that carry HGX GPU baseboards. What an attacker gets is the ability to corrupt or take over firmware-privileged execution - which on x86 means SMM and the pre-boot environment, below the hypervisor, below the host kernel, and outside anything the operator's security tooling can see. Scope is marked changed in the CVSS vector, meaning the compromise crosses a security boundary. On a GPU host this is the persistence layer under a very expensive, very heavily shared machine. The X11DPG-HGX2 is the head node board for NVIDIA HGX-2 baseboards, so this is literally GPU-platform BIOS rather than generic server BIOS.
Who can reach it
Local, high-privilege access to the host - root or equivalent on the node's operating system, with high attack complexity. The realistic actor is a tenant on leased bare metal, or an attacker who already has host root and wants to convert it into something that survives the node being wiped and re-let.
What to do
BIOS flash to version 4.4 or later from Supermicro's July 2024 BIOS advisory. BIOS updates on these boards require a host reboot and, on some SKUs, a BMC-mediated update, so this is a per-node maintenance window on machines that are usually running multi-day training jobs - schedule it into a drain cycle rather than expecting an ad-hoc window. There is no config-only mitigation: the write primitive is in the firmware itself.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.