Vulnerability CVE-2018-7112


Published: 2018-12-03

Description:
The HPE-provided Windows firmware installer for certain Gen9, Gen8, G7,and G6 HPE servers allows local disclosure of privileged information. This issue was resolved in previously provided firmware updates as follows. The HPE Windows firmware installer was updated in the system ROM updates which also addressed the original Spectre/Meltdown set of vulnerabilities. At that time, the Windows firmware installer was also updated in the versions of HPE Integrated Lights-Out 2, 3, and 4 (iLO 2, 3, and 4) listed in the security bulletin. The updated HPE Windows firmware installer was released in the system ROM and HPE Integrated Lights-Out (iLO) releases documented in earlier HPE Security Bulletins: HPESBHF03805, HPESBHF03835, HPESBHF03831. Windows-based systems that have already been updated to the system ROM or iLO versions described in these security bulletins require no further action.

Type:

CWE-200

(Information Exposure)

CVSS2 => (AV:L/AC:L/Au:N/C:C/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4.9/10
6.9/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
None
None
Affected software
HP -> Integrated lights-out 2 firmware 
HP -> Integrated lights-out 3 firmware 
HP -> Integrated lights-out 4 firmware 
HP -> Proliant dl120 g6 server firmware 
HP -> Proliant dl160 g6 server firmware 
HP -> Proliant dl170e g6 server firmware 
HP -> Proliant dl170h g6 server firmware 
HP -> Proliant dl180 g6 server firmware 
HP -> Proliant dl380 g7 server firmware 
HP -> Proliant ml110 g6 server firmware 
HP -> Proliant ml150 g6 server firmware 
HP -> Proliant sl160s g6 server firmware 
HP -> Proliant sl170z g6 server firmware 
HP -> Proliant sl2x170z g6 server firmware 
HP -> Proliant sl4545 g7 server (amd) firmware 

 References:
http://www.securitytracker.com/id/1041984
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03805en_us
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03831en_us
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03835en_us
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03869en_us

Copyright 2024, cxsecurity.com

 

Back to Top