Unrestricted IP address binding in the AMD Device Metrics Exporter (ROCm ecosystem) could allow a remote attacker to perform unauthorized changes to the GPU configuration, potentially resulting in loss of availability
The AMD Device Metrics Exporter component does not impose appropriate restrictions on IP address binding (CWE-1327 — Binding to an Unrestricted IP Address), which means the service listens on network interfaces in an uncontrolled manner. A remote attacker, without the need for authentication and without user interaction, can send requests to this service and make unauthorized changes to GPU configuration. The attack vector is network-based, and attack complexity is low, which significantly lowers the entry threshold for a potential attacker.
An attacker can make unauthorized changes to GPU configuration, which may result in loss of device availability and related systems (SA:H). Data integrity and confidentiality are not directly threatened according to available information.
Patches available from the manufacturer should be applied in accordance with references — AMD security bulletin: https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-6031.html. It is also recommended to restrict network access to the AMD Device Metrics Exporter service using a firewall or ACL rules to trusted IP addresses until the patch is deployed.
AMD Device Metrics Exporter included in the ROCm ecosystem; specific versions indicated in manufacturer references (AMD-SB-6031 bulletin)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X