Incorrect calculation in Certain HPE Apollo, XL Servers



Published: 2023-03-17
Risk Low
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2022-33972
CWE-ID CWE-682
Exploitation vector Local
Public exploit N/A
Vulnerable software
Subscribe
HPE ProLiant XL220n Gen10 Plus Server
Hardware solutions / Firmware

HPE ProLiant XL290n Gen10 Plus Server
Hardware solutions / Firmware

HPE Apollo 2000 Gen10 Plus System
Hardware solutions / Firmware

HPE Apollo 4200 Gen10 Plus System
Hardware solutions / Firmware

Vendor HPE

Security Bulletin

This security bulletin contains one low risk vulnerability.

1) Incorrect calculation

EUVDB-ID: #VU72477

Risk: Low

CVSSv3.1:

CVE-ID: CVE-2022-33972

CWE-ID: CWE-682 - Incorrect Calculation

Exploit availability: No

Description

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to incorrect calculation in microcode keying mechanism. A local user can gain access to sensitive information.

Mitigation

Install update from vendor's website.

Vulnerable software versions

HPE ProLiant XL220n Gen10 Plus Server: before 1.72_02-02-2023

HPE ProLiant XL290n Gen10 Plus Server: before 1.72_02-02-2023

HPE Apollo 2000 Gen10 Plus System: before 1.72_02-02-2023

HPE Apollo 4200 Gen10 Plus System: before 1.72_02-02-2023


CPE2.3
External links

http://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=hpesbhf04442en_us

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?



###SIDEBAR###