2018-02-15 11:02:26 -05:00
{
2019-03-17 22:26:40 +00:00
"CVE_data_meta" : {
"ASSIGNER" : "security-alert@hpe.com" ,
"ID" : "CVE-2018-7112" ,
"STATE" : "PUBLIC"
} ,
"affects" : {
"vendor" : {
"vendor_data" : [
{
"product" : {
"product_data" : [
{
"product_name" : "Windows firmware installer for Gen9, Gen8, G7,and G6 HPE servers" ,
"version" : {
"version_data" : [
{
"version_value" : " O n l y t h e W i n d o w s b a s e d f i r m w a r e i n s t a l l e r s f o r t h e f o l l o w i n g p r o d u c t s . H P E I n t e g r a t e d L i g h t s - O u t 2 ( i L O 2 ) F i r m w a r e f o r P r o L i a n t G 6 S e r v e r s - P r i o r t o v 2.33 , H P E I n t e g r a t e d L i g h t s - O u t 3 ( i L O 3 ) F i r m w a r e f o r P r o L i a n t G 7 S e r v e r s - P r i o r t o v 1.90 , H P E I n t e g r a t e d L i g h t s - O u t 4 ( i L O 4 ) F i r m w a r e f o r P r o L i a n t G e n 8 S e r v e r f i r m w a r e s - P r i o r t o v 2.60 , H P E P r o L i a n t X L 750 f G e n 9 S e r v e r f i r m w a r e - P r i o r t o 2.56 _ 0 1 -22 -2018 ( 23 F e b 2018 ) , H P E P r o L i a n t X L 740 f G e n 9 S e r v e r f i r m w a r e - P r i o r t o 2.56 _ 0 1 -22 -2018 ( 23 F e b 2018 ) , H P E P r o L i a n t X L 730 f G e n 9 S e r v e r f i r m w a r e - P r i o r t o 2.56 _ 0 1 -22 -2018 ( 23 F e b 2018 ) , H P E P r o L i a n t X L 450 G e n 9 S e r v e r f i r m w a r e - P r i o r t o 2.56 _ 0 1 -22 -2018 ( 23 F e b 2018 ) , H P E P r o L i a n t X L 270 d G e n 9 S p e c i a l S e r v e r - P r i o r t o 2.56 _ 0 1 -22 -2018 ( 23 F e b 2018 ) , H P E P r o L i a n t X L 270 d G e n 9 A c c e l e r a t o r T r a y 2 U C o n f i g u r e - t o - o r d e r S e r v e r - P r i o r t o 2.56 _ 0 1 -22 -2018 ( 23 F e b 2018 ) , H P E P r o L i a n t X L 260 a G e n 9 S e r v e r f i r m w a r e - P r i o r t o 1.60 _ 0 1 -22 -2018 ( 26 F e b 2018 ) , H P E P r o L i a n t X L 250 a G e n 9 S e r v e r f i r m w a r e - P r i o r t o 2.56 _ 0 1 -22 -2018 ( 23 F e b 2018 ) , H P E P r o L i a n t X L 230 a G e n 9 S e r v e r f i r m w a r e - P r i o r t o 2.56 _ 0 1 -22 -2018 ( 23 F e b 2018 ) , H P E P r o L i a n t X L 190 r G e n 9 S e r v e r f i r m w a r e - P r i o r t o 2.56 _ 0 1 -22 -2018 ( 23 F e b 2018 ) , H P E P r o L i a n t X L 170 r G e n 9 S e r v e r f i r m w a r e - P r i o r t o 2.56 _ 0 1 -22 -2018 ( 23 F e b 2018 ) , H P E P r o L i a n t D L 560 G e n 9 S e r v e r f i r m w a r e - P r i o r t o 2.56 _ 0 1 -22 -2018 ( 23 F e b 2018 ) , H P E P r o L i a n t D L 380 G e n 9 S e r v e r f i r m w a r e - P r i o r t o 2.56 _ 0 1 -22 -2018 ( 23 F e b 2018 ) , H P E P r o L i a n t D L 360 G e n 9 S e r v e r f i r m w a r e - P r i o r t o 2.56 _ 0 1 -22 -2018 ( 23 F e b 2018 ) , H P E P r o L i a n t D L 180 G e n 9 S e r v e r f i r m w a r e - P r i o r t o 2.56 _ 0 1 -22 -2018 ( 23 F e b 2018 ) , H P E P r o L i a n t D L 160 G e n 9 S e r v e r f i r m w a r e - P r i o r t o 2.56 _ 0 1 -22 -2018 ( 23 F e b 2018 ) , H P E P r o L i a n t D L 120 G e n 9 S e r v e r f i r m w a r e - P r i o r t o 2.56 _ 0 1 -22 -2018 ( 23 F e b 2018 ) . H P E P r o L i a n t D L 80 G e n 9 S e r v e r f i r m w a r e - P r i o r t o 2.56 _ 0 1 -22 -2018 ( 23 F e b 2018 ) , H P E P r o L i a n t D L 60 G e n 9 S e r v e r f i r m w a r e - P r i o r t o 2.56 _ 0 1 -22 -2018 ( 23 F e b 2018 ) , H P E P r o L i a n t D L 20 G e n 9 S e r v e r f i r m w a r e - P r i o r t o 2.56 _ 0 1 -22 -2018 ( 27 F e b 2018 ) , H P E P r o L i a n t M L 350 G e n 9 S e r v e r f i r m w a r e - P r i o r t o 2.56 _ 0 1 -22 -2018 ( 23 F e b 2018 ) , H P E P r o L i a n t M L 150 G e n 9 S e r v e r f i r m w a r e - P r i o r t o 2.56 _ 0 1 -22 -2018 ( 23 F e b 2018 ) , H P E P r o L i a n t M L 110 G e n 9 S e r v e r f i r m w a r e - P r i o r t o 2.56 _ 0 1 -22 -2018 ( 23 F e b 2018 ) , H P E P r o L i a n t M L 30 G e n 9 S e r v e r f i r m w a r e - P r i o r t o 2.56 _ 0 1 -22 -2018 ( 27 F e b 2018 ) , H P E P r o L i a n t M L 10 G e n 9 S e r v e r f i r m w a r e - P r i o r t o 2018.01 . 22 ( 22 M a r 2018 ) , H P E P r o L i a n t B L 660 c G e n 9 S e r v e r f i r m w a r e - P r i o r t o 2.56 _ 0 1 -22 -2018 ( 23 F e b 2018 ) , H P E P r o L i a n t B L 460 c G e n 9 S e r v e r f i r m w a r e B l a d e - P r i o r t o 2.56 _ 0 1 -22 -2018 ( 23 F e b 2018 ) , H P E P r o L i a n t W S 460 c G e n 9 W o r k s t a t i o n - P r i o r t o 2.56 _ 0 1 -22 -2018 ( 23 F e b 2018 ) , H P E P r o L i a n t D L 380 e G e n 8 S e r v e r f i r m w a r e - P r i o r t o 2018.01 . 22 ( 2 M a r 2018 ) , H P E P r o L i a n t D L 360 p G e n 8 S e r v e r f i r m w a r e - P r i o r t o 2018.01 . 22 ( 2 M a r 2018 ) , H P E P r o L i a n t D L 360 e G e n 8 S e r v e r f i r m w a r e - P r i o r t o 2018.01 . 22 ( 2 M a r 2018 ) , H P E P r o L i a n t D L 320 e G e n 8 S e r v e r f i r m w a r e - P r i o r t o 2018.01 . 22 ( 5 M a r 2018 ) , H P E P r o L i a n t D L 320 e G e n 8 v 2 S e r v e r f i r m w a r e - P r i o r t o 2018.01 . 22 ( 23 F e b 2018 ) , H P E P r o L i a n t D L 160 G e n 8 S e r v e r f i r m w a r e - P r i o r t o 2018.01 . 22 ( 2 M a r 2018 ) , H P E P r o L i a n t S L 250 s G e n 8 S e r v e r f i r m w a r e - P r i o r t o 2018.01 . 22 ( 2 M a r 2018 ) , H P E P r o L i a n t S L 210 t G e n 8 S e r v e r f i r m w a r e - P r i o r t o 2018.01 . 22 ( 2 M a r 2018 ) , H P E P r o L i a n t B L 660 c G e n 8 S e r v e r f i r m w a r e B l a d e - P r i o r t o 2018.01 . 22 ( 2 M a r 2018 ) , H P E P r o L i a n t B L 465 c G e n 8 ( A M D ) - P r i o r t o 2018.03 . 14 ( 12 A p r 2018 ) , H P E P r o L i a n t B L 460 c G e n 8 S e r v e r f i r m w a r e B l a d e - P r i o r t o 2018.01 . 22 ( 2 M a r 2018 ) , H P E P r o L i a n t B L 420 c G e n 8 S e r v e r f i r m w a r e - P r i o r t o 2018.01 . 22 ( 2 M a r 2018 ) , H P E P r o L i a n t S L 4540 G e n 8 1 N o d e S e r v e r f i r m w a r e - P r i o r t o 2018.01 . 22 ( 2 M a r 2018 ) , H P E P r o L i a n t S L 270 s G e n 8 S e r v e r f i r m w a r e - P r i o r t o 2018.01 . 22 ( 2 M a r 2018 ) , H P E P r o L i a n t D L 580 G e n 8 S e r v e r f i r m w a r e - P r i o r t o 2.00 _ 0 2 -22 -2018 ( 2 M a r 2018 ) , H P E P r o L i a n t D L 560 G e n 8 S e r v e r f i r m w a r e - P r i o r t o 2018.01 . 22 ( 2 M a r 2018 ) , H P E P r o L i a n t D L 380 p G e n 8 S e r v e r f i r m w a r e - P r i o r t o 2018.01 . 22 ( 2 M a r 2018 ) , H P E P r o L i a n t D L 385 p G e n 8 ( A M D ) - P r i o r t o 2018.03 . 14 ( 12 A p r 2018 ) , H P E P r o L i a n t
}
]
}
}
]
} ,
"vendor_name" : "Hewlett Packard Enterprise"
}
]
}
} ,
"data_format" : "MITRE" ,
"data_type" : "CVE" ,
"data_version" : "4.0" ,
"description" : {
"description_data" : [
2018-12-03 09:06:58 -05:00
{
2019-03-17 22:26:40 +00:00
"lang" : "eng" ,
"value" : "The HPE-provided Windows firmware installer for certain Gen9, Gen8, G7,and G6 HPE servers allows local disclosure of privileged information. This issue was resolved in previously provided firmware updates as follows. The HPE Windows firmware installer was updated in the system ROM updates which also addressed the original Spectre/Meltdown set of vulnerabilities. At that time, the Windows firmware installer was also updated in the versions of HPE Integrated Lights-Out 2, 3, and 4 (iLO 2, 3, and 4) listed in the security bulletin. The updated HPE Windows firmware installer was released in the system ROM and HPE Integrated Lights-Out (iLO) releases documented in earlier HPE Security Bulletins: HPESBHF03805, HPESBHF03835, HPESBHF03831. Windows-based systems that have already been updated to the system ROM or iLO versions described in these security bulletins require no further action."
2018-12-03 09:06:58 -05:00
}
2019-03-17 22:26:40 +00:00
]
} ,
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"lang" : "eng" ,
"value" : "local disclosure of privileged information"
}
]
}
]
} ,
"references" : {
"reference_data" : [
{
"name" : "1041984" ,
"refsource" : "SECTRACK" ,
"url" : "http://www.securitytracker.com/id/1041984"
} ,
{
"name" : "https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03831en_us" ,
"refsource" : "CONFIRM" ,
"url" : "https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03831en_us"
} ,
{
"name" : "https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03805en_us" ,
"refsource" : "CONFIRM" ,
"url" : "https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03805en_us"
} ,
{
"name" : "https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03835en_us" ,
"refsource" : "CONFIRM" ,
"url" : "https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03835en_us"
} ,
{
"name" : "https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03869en_us" ,
"refsource" : "CONFIRM" ,
"url" : "https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03869en_us"
}
]
}
}