Horizon Alert
Summary of the vulnerability and why it matters
This advisory details a critical vulnerability in AmpereOne devices. An improperly formed command could allow unauthorized control over the PCIe driver, potentially leading to significant data compromise and system disruption. The exposure is external, meaning it could be exploited over a network.
- Flaw in device firmware could allow unauthorized control.
- External access means it could affect systems remotely.
- Confirm relevance and exposure for affected devices.
Attack Path
How an attacker could exploit the issue
An attacker could initiate a chain of actions to reach the vulnerable component within the device's firmware. This journey begins with an incorrectly formed call to the system management controller, targeting the UEFI-MM PCIe driver. If successful, this could lead to unauthorized modifications of memory within the PCIe driver's address space.
- Entry condition: Network access to the device.
- Trigger point: Malformed SMC call to UEFI-MM PCIe driver.
- Resulting risk: Out-of-bounds write in PCIe driver.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could affect the integrity and availability of Ampere devices by allowing an out-of-bounds write in the PCIe driver's S-EL0 address space. This occurs when a specifically malformed SMC call is made to the UEFI-MM PCIe driver.
- Device firmware integrity.
- Malformed SMC call to driver.
- Potential system instability or data corruption.
Operational Fix
Recommended remediation, mitigation, and detection steps
This critical vulnerability impacting AmpereOne devices requires coordination between infrastructure and platform teams, as they manage the firmware and underlying hardware. The immediate priority is to conduct an inventory of all affected AmpereOne devices, determine their business criticality and network exposure, and identify the specific system owners responsible for each. A risk-based remediation plan, including vendor coordination with Ampere Computing, should then be developed and executed.
- Identify affected devices and ownership.
- Verify network reachability and business impact.
- Plan remediation with vendor support.