Improper access control in Intel products - CVE-2022-21216
Published: February 21, 2023
Vulnerability details
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in out-of-band management in Intel processors. A remote privileged user on the local network can bypass implemented security restrictions and gain unauthorized access to the application.
Affected software
Intel Atom Processor P5900
Intel Atom Processor P5300
Intel Atom Processor C5300
PowerEdge T150
PowerEdge R250
PowerEdge T350
PowerEdge R350
PowerEdge XR11
PowerEdge XR12
PowerEdge R750XS
PowerEdge R650XS
PowerEdge R450
PowerEdge T550
PowerEdge MX750c
PowerEdge C6520
PowerEdge R650
PowerEdge R750XA
PowerEdge R550
PowerEdge R750
HPE Edgeline e920t Server Blade
HPE Edgeline e920d Server Blade
HPE Edgeline e920 Server Blade
HPE StoreEasy 1660 Storage
HPE ProLiant DL380 Gen10 Plus server
HPE ProLiant DL360 Gen10 Server
HPE ProLiant DL110 Gen10 Plus Telco server
HPE ProLiant XL220n Gen10 Plus Server
HPE ProLiant XL290n Gen10 Plus Server
HPE Apollo 2000 Gen10 Plus System
HPE Apollo 4200 Gen10 Plus System
HPE Synergy 480 Gen10 Compute Module
HPE ProLiant DX380 Gen10 Plus server
HPE ProLiant DX360 Gen10 Plus server
HPE StoreEasy 1860 Storage
PowerEdge R340
PowerEdge R240
PowerEdge T340
PowerEdge T140
PowerEdge MX840C
PowerEdge XE7440
PowerEdge XE2420
PowerEdge R740
PowerEdge R740XD
PowerEdge R640
PowerEdge R940
PowerEdge R540
PowerEdge R440
PowerEdge T440
PowerEdge XR2
PowerEdge R740XD2
PowerEdge R840
PowerEdge R940XA
PowerEdge T640
PowerEdge C6420
PowerEdge M640
PowerEdge XE7420
PowerEdge DSS8440
PowerEdge C4140
PowerEdge MX740C
PowerEdge M640P
PowerEdge FC640
Amazon Linux AMI
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
SUSE Enterprise Storage
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Basesystem Module
openSUSE Leap
Ubuntu
Fedora
Isolation Segment
IBM Qradar SIEM
intel-microcode (Ubuntu package)
microcode_ctl
redhat-release-virtualization-host (Red Hat package)
ucode-intel-debugsource
ucode-intel
ucode-intel-debuginfo
PowerFlex Appliance
PowerFlex rack
RecoverPoint for VMs
How to mitigate CVE-2022-21216
PowerFlex Appliance - update to IC 38.363.02
PowerEdge T150 - update to 1.5.0
PowerEdge R250 - update to 1.5.0
PowerEdge T350 - update to 1.5.0
PowerEdge R350 - update to 1.5.0
PowerEdge XR11 - update to 1.9.2
PowerEdge XR12 - update to 1.9.2
PowerEdge R750XS - update to 1.9.2
PowerEdge R650XS - update to 1.9.2
PowerEdge R450 - update to 1.9.2
PowerEdge T550 - update to 1.9.2
PowerEdge MX750c - update to 1.9.2
PowerEdge C6520 - update to 1.9.2
PowerEdge R650 - update to 1.9.2
PowerEdge R750XA - update to 1.9.2
PowerEdge R550 - update to 1.9.2
PowerEdge R750 - update to 1.9.2
HPE Edgeline e920t Server Blade - update to 1.66_02-02-2023
HPE Edgeline e920d Server Blade - update to 1.66_02-02-2023
HPE Edgeline e920 Server Blade - update to 1.66_02-02-2023
HPE StoreEasy 1660 Storage - update to 1.72_02-02-2023
HPE ProLiant DL380 Gen10 Plus server - update to 1.72_02-02-2023
HPE ProLiant DL360 Gen10 Server - update to 1.72_02-02-2023
HPE ProLiant DL110 Gen10 Plus Telco server - update to 1.72_02-02-2023
HPE ProLiant XL220n Gen10 Plus Server - update to 1.72_02-02-2023
HPE ProLiant XL290n Gen10 Plus Server - update to 1.72_02-02-2023
HPE Apollo 2000 Gen10 Plus System - update to 1.72_02-02-2023
HPE Apollo 4200 Gen10 Plus System - update to 1.72_02-02-2023
HPE Synergy 480 Gen10 Compute Module - update to 1.72_02-02-2023
HPE ProLiant DX380 Gen10 Plus server - update to 1.72_02-02-2023
HPE ProLiant DX360 Gen10 Plus server - update to 1.72_02-02-2023
HPE StoreEasy 1860 Storage - update to 1.72_02-02-2023
microcode_ctl - update to 2.1-53
microcode_ctl - addressed in versions 2.1-53.1.fc37, 2.1-53.2.fc37, 2.1-55.fc38, 2.1-55.1.fc38
PowerEdge R340 - update to 2.12.2
PowerEdge R240 - update to 2.12.2
PowerEdge T340 - update to 2.12.2
PowerEdge T140 - update to 2.12.2
PowerEdge MX840C - update to 2.17.1
PowerEdge XE7440 - update to 2.17.1
PowerEdge XE2420 - update to 2.17.1
PowerEdge R740 - update to 2.17.1
PowerEdge R740XD - update to 2.17.1
PowerEdge R640 - update to 2.17.1
PowerEdge R940 - update to 2.17.1
PowerEdge R540 - update to 2.17.1
PowerEdge R440 - update to 2.17.1
PowerEdge T440 - update to 2.17.1
PowerEdge XR2 - update to 2.17.1
PowerEdge R740XD2 - update to 2.17.1
PowerEdge R840 - update to 2.17.1
PowerEdge R940XA - update to 2.17.1
PowerEdge T640 - update to 2.17.1
PowerEdge C6420 - update to 2.17.1
PowerEdge M640 - update to 2.17.1
PowerEdge XE7420 - update to 2.17.1
PowerEdge DSS8440 - update to 2.17.1
PowerEdge C4140 - update to 2.17.1
PowerEdge MX740C - update to 2.17.1
PowerEdge M640P - update to 2.17.1
PowerEdge FC640 - update to 2.17.1
PowerFlex rack - update to 3.6.3.2
redhat-release-virtualization-host (Red Hat package) - update to 4.5.3-9.el8ev
RecoverPoint for VMs - update to 6.0.SP1.P1
ucode-intel-debugsource - addressed in versions 20230214-3.49.1, 20230214-13.104.1
ucode-intel - addressed in versions 20230214-3.49.1, 20230214-13.104.1, 20230214-150100.3.217.1, 20230214-150200.21.1
ucode-intel-debuginfo - addressed in versions 20230214-3.49.1, 20230214-13.104.1
External References
Related Security Bulletins
- Privilege escalation in Intel Atom and Xeon Scalable processors
- SUSE update for ucode-intel
- SUSE update for ucode-intel
- SUSE update for ucode-intel
- Multiple vulnerabilities in Dell PowerEdge Server firmware
- Ubuntu update for intel-microcode
- SUSE update for ucode-intel
- Improper access control in HPE Synergy Servers
- Improper access control in Certain HPE ProLiant DX Servers
- Improper access control in Certain HPE StoreEasy Servers
- Improper access control in Certain HPE ProLiant Servers
- Improper access control in Certain HPE Edgeline Servers
- Improper access control in Certain HPE Apollo, XL Servers
- Multiple vulnerabilities in Dell PowerFlex Appliance
- VMware Tanzu Isolation Segment update for Intel Microcode
- Multiple vulnerabilities in Dell PowerFlex Rack
- Fedora 37 update for microcode_ctl
- Fedora 38 update for microcode_ctl
- Fedora 38 update for microcode_ctl
- Fedora 37 update for microcode_ctl
- Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 update for redhat-release-virtualization-host and redhat-virtualization-host
- Improper access control in IBM QRadar SIEM M7 Appliances
- Multiple vulnerabilities in Dell RecoverPoint for Virtual Machines
- Amazon Linux AMI update for microcode_ctl