Multiple vulnerabilities in Certain HPE Apollo, XL Servers



Published: 2023-03-17
Risk Low
Patch available YES
Number of vulnerabilities 4
CVE-ID CVE-2021-0187
CVE-2022-26343
CVE-2022-26837
CVE-2022-32231
CWE-ID CWE-284
CWE-20
CWE-665
Exploitation vector Local
Public exploit N/A
Vulnerable software
Subscribe
HPE ProLiant XL70d Gen10 Server
Hardware solutions / Firmware

HPE ProLiant XL230k Gen10 Server
Hardware solutions / Firmware

HPE ProLiant XL170r Gen10 Server
Hardware solutions / Firmware

HPE ProLiant XL190r Gen10 Server
Hardware solutions / Firmware

HPE Apollo 6500 Gen10 System
Hardware solutions / Firmware

HPE Apollo 4510 Gen10 System
Hardware solutions / Firmware

HPE Apollo 4200 Gen10 Server
Hardware solutions / Firmware

HPE Apollo 2000 System ROM
Hardware solutions / Firmware

HPE ProLiant XL450 Gen10 Server
Hardware solutions / Firmware

HPE Apollo 2000 Gen10 Plus System
Hardware solutions / Firmware

HPE ProLiant XL220n Gen10 Plus Server
Hardware solutions / Firmware

HPE ProLiant XL290n Gen10 Plus Server
Hardware solutions / Firmware

HPE Apollo 4200 Gen10 Plus System
Hardware solutions / Firmware

Vendor HPE

Security Bulletin

This security bulletin contains information about 4 vulnerabilities.

1) Improper access control

EUVDB-ID: #VU72455

Risk: Low

CVSSv3.1:

CVE-ID: CVE-2021-0187

CWE-ID: CWE-284 - Improper Access Control

Exploit availability: No

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to improper access restrictions in the BIOS firmware. A local user can execute arbitrary code with elevated privileges.

Mitigation

Install update from vendor's website.

Vulnerable software versions

HPE ProLiant XL70d Gen10 Server : before 2.76_02-09-2023

HPE ProLiant XL230k Gen10 Server: before 2.76_02-09-2023

HPE ProLiant XL170r Gen10 Server: before 2.76_02-09-2023

HPE ProLiant XL190r Gen10 Server: before 2.76_02-09-2023

HPE Apollo 6500 Gen10 System: before 2.76_02-09-2023

HPE Apollo 4510 Gen10 System: before 2.76_02-09-2023

HPE Apollo 4200 Gen10 Server: before 2.76_02-09-2023

HPE Apollo 2000 System ROM: before 2.76_02-09-2023

HPE ProLiant XL450 Gen10 Server: before 2.76_02-09-2023

HPE Apollo 2000 Gen10 Plus System: before 2.76_02-09-2023

HPE ProLiant XL220n Gen10 Plus Server: before 1.72_02-02-2023

HPE ProLiant XL290n Gen10 Plus Server: before 1.72_02-02-2023

HPE Apollo 4200 Gen10 Plus System: before 1.72_02-02-2023


CPE2.3
External links

http://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=hpesbhf04440en_us

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

2) Improper access control

EUVDB-ID: #VU72449

Risk: Low

CVSSv3.1:

CVE-ID: CVE-2022-26343

CWE-ID: CWE-284 - Improper Access Control

Exploit availability: No

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to improper access restrictions in the BIOS firmware. A local privileged user can execute arbitrary code with elevated privileges.

Mitigation

Install update from vendor's website.

Vulnerable software versions

HPE ProLiant XL70d Gen10 Server : before 2.76_02-09-2023

HPE ProLiant XL230k Gen10 Server: before 2.76_02-09-2023

HPE ProLiant XL170r Gen10 Server: before 2.76_02-09-2023

HPE ProLiant XL190r Gen10 Server: before 2.76_02-09-2023

HPE Apollo 6500 Gen10 System: before 2.76_02-09-2023

HPE Apollo 4510 Gen10 System: before 2.76_02-09-2023

HPE Apollo 4200 Gen10 Server: before 2.76_02-09-2023

HPE Apollo 2000 System ROM: before 2.76_02-09-2023

HPE ProLiant XL450 Gen10 Server: before 2.76_02-09-2023

HPE Apollo 2000 Gen10 Plus System: before 2.76_02-09-2023

HPE ProLiant XL220n Gen10 Plus Server: before 1.72_02-02-2023

HPE ProLiant XL290n Gen10 Plus Server: before 1.72_02-02-2023

HPE Apollo 4200 Gen10 Plus System: before 1.72_02-02-2023


CPE2.3
External links

http://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=hpesbhf04440en_us

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

3) Input validation error

EUVDB-ID: #VU72452

Risk: Low

CVSSv3.1:

CVE-ID: CVE-2022-26837

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to insufficient validation of user-supplied input in the BIOS firmware. A local user can execute arbitrary code with elevated privileges.

Mitigation

Install update from vendor's website.

Vulnerable software versions

HPE ProLiant XL70d Gen10 Server : before 2.76_02-09-2023

HPE ProLiant XL230k Gen10 Server: before 2.76_02-09-2023

HPE ProLiant XL170r Gen10 Server: before 2.76_02-09-2023

HPE ProLiant XL190r Gen10 Server: before 2.76_02-09-2023

HPE Apollo 6500 Gen10 System: before 2.76_02-09-2023

HPE Apollo 4510 Gen10 System: before 2.76_02-09-2023

HPE Apollo 4200 Gen10 Server: before 2.76_02-09-2023

HPE Apollo 2000 System ROM: before 2.76_02-09-2023

HPE ProLiant XL450 Gen10 Server: before 2.76_02-09-2023

HPE Apollo 2000 Gen10 Plus System: before 2.76_02-09-2023

HPE ProLiant XL220n Gen10 Plus Server: before 1.72_02-02-2023

HPE ProLiant XL290n Gen10 Plus Server: before 1.72_02-02-2023

HPE Apollo 4200 Gen10 Plus System: before 1.72_02-02-2023


CPE2.3
External links

http://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=hpesbhf04440en_us

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

4) Improper Initialization

EUVDB-ID: #VU72451

Risk: Low

CVSSv3.1:

CVE-ID: CVE-2022-32231

CWE-ID: CWE-665 - Improper Initialization

Exploit availability: No

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to improper initialization in the BIOS firmware. A local user can run a specially crafted application to execute arbitrary code with escalated privileges on the system.

Mitigation

Install update from vendor's website.

Vulnerable software versions

HPE ProLiant XL70d Gen10 Server : before 2.76_02-09-2023

HPE ProLiant XL230k Gen10 Server: before 2.76_02-09-2023

HPE ProLiant XL170r Gen10 Server: before 2.76_02-09-2023

HPE ProLiant XL190r Gen10 Server: before 2.76_02-09-2023

HPE Apollo 6500 Gen10 System: before 2.76_02-09-2023

HPE Apollo 4510 Gen10 System: before 2.76_02-09-2023

HPE Apollo 4200 Gen10 Server: before 2.76_02-09-2023

HPE Apollo 2000 System ROM: before 2.76_02-09-2023

HPE ProLiant XL450 Gen10 Server: before 2.76_02-09-2023

HPE Apollo 2000 Gen10 Plus System: before 2.76_02-09-2023

HPE ProLiant XL220n Gen10 Plus Server: before 1.72_02-02-2023

HPE ProLiant XL290n Gen10 Plus Server: before 1.72_02-02-2023

HPE Apollo 4200 Gen10 Plus System: before 1.72_02-02-2023


CPE2.3
External links

http://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=hpesbhf04440en_us

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?



###SIDEBAR###