Out-of-bounds write in 3rd Generation Intel Xeon Scalable Processors - CVE-2021-33060
Published: August 15, 2022
Vulnerability identifier: #VU66499
CSH Severity: Low
CVSS v4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-33060
CWE-ID: CWE-787
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to compromise vulnerable system.
The vulnerability exists due to a boundary error in the BIOS firmware. A local user can trigger out-of-bounds write and execute arbitrary code on the target system with elevated privileges.
Affected software
3rd Generation Intel Xeon Scalable Processors
Superdome Flex 280 Server
HPE ProLiant DX380 Gen10 Plus server
HPE ProLiant DX360 Gen10 Plus server
HPE ProLiant DL380 Gen10 Plus server
HPE ProLiant DL360 Gen10 Plus server
HPE ProLiant DL110 Gen10 Plus Telco server
HPE Edgeline e920t Server Blade
HPE Edgeline e920d Server Blade
HPE Edgeline e920 Server Blade
HPE Apollo 4200 Gen10 Plus System
HPE Apollo 2000 Gen10 Plus System
HPE ProLiant XL290n Gen10 Plus Server
HPE ProLiant XL220n Gen10 Plus Server
EMC Integrated Data Protection Appliance
F5OS
HPE Synergy 480 Gen10 Plus Compute Module
Superdome Flex 280 Server
HPE ProLiant DX380 Gen10 Plus server
HPE ProLiant DX360 Gen10 Plus server
HPE ProLiant DL380 Gen10 Plus server
HPE ProLiant DL360 Gen10 Plus server
HPE ProLiant DL110 Gen10 Plus Telco server
HPE Edgeline e920t Server Blade
HPE Edgeline e920d Server Blade
HPE Edgeline e920 Server Blade
HPE Apollo 4200 Gen10 Plus System
HPE Apollo 2000 Gen10 Plus System
HPE ProLiant XL290n Gen10 Plus Server
HPE ProLiant XL220n Gen10 Plus Server
EMC Integrated Data Protection Appliance
F5OS
HPE Synergy 480 Gen10 Plus Compute Module
How to mitigate CVE-2021-33060
Install updates from vendor's website.
Superdome Flex 280 Server - update to 1.35.12
HPE ProLiant DX380 Gen10 Plus server - update to 1.62_07-14-2022
HPE ProLiant DX360 Gen10 Plus server - update to 1.62_07-14-2022
HPE Synergy 480 Gen10 Plus Compute Module - update to 1.62_07-14-2022
HPE ProLiant DL380 Gen10 Plus server - update to 1.62_07-14-2022
HPE ProLiant DL360 Gen10 Plus server - update to 1.62_07-14-2022
HPE ProLiant DL110 Gen10 Plus Telco server - update to 1.62_07-14-2022
HPE Edgeline e920t Server Blade - update to 1.62_08-16-2022
HPE Edgeline e920d Server Blade - update to 1.62_08-16-2022
HPE Edgeline e920 Server Blade - update to 1.62_08-16-2022
HPE Apollo 4200 Gen10 Plus System - update to 1.64_08-11-2022
HPE Apollo 2000 Gen10 Plus System - update to 1.64_08-11-2022
HPE ProLiant XL290n Gen10 Plus Server - update to 1.64_08-11-2022
HPE ProLiant XL220n Gen10 Plus Server - update to 1.64_08-11-2022
HPE ProLiant DX380 Gen10 Plus server - update to 1.62_07-14-2022
HPE ProLiant DX360 Gen10 Plus server - update to 1.62_07-14-2022
HPE Synergy 480 Gen10 Plus Compute Module - update to 1.62_07-14-2022
HPE ProLiant DL380 Gen10 Plus server - update to 1.62_07-14-2022
HPE ProLiant DL360 Gen10 Plus server - update to 1.62_07-14-2022
HPE ProLiant DL110 Gen10 Plus Telco server - update to 1.62_07-14-2022
HPE Edgeline e920t Server Blade - update to 1.62_08-16-2022
HPE Edgeline e920d Server Blade - update to 1.62_08-16-2022
HPE Edgeline e920 Server Blade - update to 1.62_08-16-2022
HPE Apollo 4200 Gen10 Plus System - update to 1.64_08-11-2022
HPE Apollo 2000 Gen10 Plus System - update to 1.64_08-11-2022
HPE ProLiant XL290n Gen10 Plus Server - update to 1.64_08-11-2022
HPE ProLiant XL220n Gen10 Plus Server - update to 1.64_08-11-2022
External References
Related Security Bulletins
- Out-of-bounds write in Intel Processors
- Privilege escalation in F5OS-A BIOS firmware
- Out-of-bounds write in Certain HPE Edgeline Servers
- Out-of-bounds write in Certain HPE ProLiant Apollo, XL Servers
- Out-of-bounds write in Certain HPE ProLiant DX Servers
- Out-of-bounds write in HPE Superdome Flex 280 Servers
- Out-of-bounds write in Certain HPE Synergy Servers
- Out-of-bounds write in Certain HPE ProLiant DL Servers
- Multiple vulnetabilities in Dell EMC Integrated Data Protection Appliance