chipsec
chipsec copied to clipboard
Question about disabled TCO SMI
Hi,
In bios_smi.py, gbl_smi_en being zero immediately results in failure of validation (ie, concluded to be vulnerable) but tco_en only generates warning. Is not disabled TCO SMI indicative of the same vulnerability as disabled global SMI?
I wondered this, because I assumed that TCO SMI is what SMM needs to reset the bit, and so, disabled TCO SMI itself is vulnerable enough.
Thanks for the report. We will take a look at the module.