I have an older ESXi server functioning as a home lab. It is based on the Westmere architecture (Xeon X5670), and will likely *never* see a BIOS patch from the vendor to address Spectre. I *have* applied the available 6.5U1 patches for Meltdown and Spectre. I believe this means that I am now immune to Meltdown, but I'm not sure how well protected I am from Spectre, since immunizing against Spectre usually requires a BIOS update.
So how vulnerable to Spectre am I with an unpatched BIOS?