Out-of-bounds write in 3rd Generation Intel Xeon Scalable Processors - CVE-2021-33060

 

Out-of-bounds write in 3rd Generation Intel Xeon Scalable Processors - CVE-2021-33060

Published: August 15, 2022


Vulnerability identifier: #VU66499
CSH Severity: Low
CVSS v4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-33060
CWE-ID: CWE-787
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to compromise vulnerable system.

The vulnerability exists due to a boundary error in the BIOS firmware. A local user can trigger out-of-bounds write and execute arbitrary code on the target system with elevated privileges.


Affected software

3rd Generation Intel Xeon Scalable Processors
Superdome Flex 280 Server
HPE ProLiant DX380 Gen10 Plus server
HPE ProLiant DX360 Gen10 Plus server
HPE ProLiant DL380 Gen10 Plus server
HPE ProLiant DL360 Gen10 Plus server
HPE ProLiant DL110 Gen10 Plus Telco server
HPE Edgeline e920t Server Blade
HPE Edgeline e920d Server Blade
HPE Edgeline e920 Server Blade
HPE Apollo 4200 Gen10 Plus System
HPE Apollo 2000 Gen10 Plus System
HPE ProLiant XL290n Gen10 Plus Server
HPE ProLiant XL220n Gen10 Plus Server
EMC Integrated Data Protection Appliance
F5OS
HPE Synergy 480 Gen10 Plus Compute Module

How to mitigate CVE-2021-33060

Install updates from vendor's website.

Superdome Flex 280 Server - update to 1.35.12
HPE ProLiant DX380 Gen10 Plus server - update to 1.62_07-14-2022
HPE ProLiant DX360 Gen10 Plus server - update to 1.62_07-14-2022
HPE Synergy 480 Gen10 Plus Compute Module - update to 1.62_07-14-2022
HPE ProLiant DL380 Gen10 Plus server - update to 1.62_07-14-2022
HPE ProLiant DL360 Gen10 Plus server - update to 1.62_07-14-2022
HPE ProLiant DL110 Gen10 Plus Telco server - update to 1.62_07-14-2022
HPE Edgeline e920t Server Blade - update to 1.62_08-16-2022
HPE Edgeline e920d Server Blade - update to 1.62_08-16-2022
HPE Edgeline e920 Server Blade - update to 1.62_08-16-2022
HPE Apollo 4200 Gen10 Plus System - update to 1.64_08-11-2022
HPE Apollo 2000 Gen10 Plus System - update to 1.64_08-11-2022
HPE ProLiant XL290n Gen10 Plus Server - update to 1.64_08-11-2022
HPE ProLiant XL220n Gen10 Plus Server - update to 1.64_08-11-2022

External References

Related Security Bulletins