Risk | Low |
Patch available | YES |
Number of vulnerabilities | 1 |
CVE-ID | CVE-2022-33972 |
CWE-ID | CWE-682 |
Exploitation vector | Local |
Public exploit | N/A |
Vulnerable software Subscribe |
HPE ProLiant XL220n Gen10 Plus Server Hardware solutions / Firmware HPE ProLiant XL290n Gen10 Plus Server Hardware solutions / Firmware HPE Apollo 2000 Gen10 Plus System Hardware solutions / Firmware HPE Apollo 4200 Gen10 Plus System Hardware solutions / Firmware |
Vendor | HPE |
This security bulletin contains one low risk vulnerability.
EUVDB-ID: #VU72477
Risk: Low
CVSSv3.1:
CVE-ID: CVE-2022-33972
CWE-ID:
CWE-682 - Incorrect Calculation
Exploit availability: No
DescriptionThe vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to incorrect calculation in microcode keying mechanism. A local user can gain access to sensitive information.
Install update from vendor's website.
Vulnerable software versionsHPE ProLiant XL220n Gen10 Plus Server: before 1.72_02-02-2023
HPE ProLiant XL290n Gen10 Plus Server: before 1.72_02-02-2023
HPE Apollo 2000 Gen10 Plus System: before 1.72_02-02-2023
HPE Apollo 4200 Gen10 Plus System: before 1.72_02-02-2023
http://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=hpesbhf04442en_us
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?