Improper access control in 3rd Generation Intel Xeon Scalable Processors and Intel Xeon D Processors - CVE-2023-23908
Published: August 11, 2023
Vulnerability identifier: #VU79377
CSH Severity: Low
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-23908
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to improper access restrictions. A local privileged user can gain access to sensitive information.
Affected software
3rd Generation Intel Xeon Scalable Processors
Intel Xeon D Processors
HPE Edgeline e920 Server Blade
HPE Edgeline e920t Server Blade
HPE Edgeline e920d Server Blade
HPE ProLiant DL380 Gen10 Plus server
HPE ProLiant DL360 Gen10 Plus server
HPE ProLiant DL110 Gen10 Plus Telco server
HPE ProLiant XL220n Gen10 Plus Server
HPE StoreEasy 1660 Storage
HPE ProLiant DX220n Gen10 Plus server
HPE ProLiant DX360 Gen10 Plus server
HPE ProLiant DX380 Gen10 Plus server
HPE Apollo 4200 Gen10 Plus System
HPE ProLiant XL290n Gen10 Plus Server
HPE Apollo 2000 Gen10 Plus System
HPE StoreEasy 1860 Storage
Precision 7960 XL Rack
Precision 7920 XL Rack
Precision 7920 Rack
HPE SimpliVity 380 Gen10 Plus
Amazon Linux AMI
Debian Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 12
F5OS
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
SUSE Enterprise Storage
SUSE Linux Enterprise Server 12 SP2 BCL
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Basesystem Module
openSUSE Leap
Ubuntu
Anolis OS
Fedora
VMware Tanzu Application Service for VMs
Isolation Segment
intel-microcode (Ubuntu package)
microcode_ctl
intel-microcode (Debian package)
ucode-intel
ucode-intel-debuginfo
ucode-intel-debugsource
HPE Synergy 480 Gen10 Plus Compute Module
Precision 7960 Rack
PowerSwitch Z9664F-ON
Dell PowerProtect Cyber Recovery
VMware Tanzu Operations Manager
RecoverPoint for VMs
Intel Xeon D Processors
HPE Edgeline e920 Server Blade
HPE Edgeline e920t Server Blade
HPE Edgeline e920d Server Blade
HPE ProLiant DL380 Gen10 Plus server
HPE ProLiant DL360 Gen10 Plus server
HPE ProLiant DL110 Gen10 Plus Telco server
HPE ProLiant XL220n Gen10 Plus Server
HPE StoreEasy 1660 Storage
HPE ProLiant DX220n Gen10 Plus server
HPE ProLiant DX360 Gen10 Plus server
HPE ProLiant DX380 Gen10 Plus server
HPE Apollo 4200 Gen10 Plus System
HPE ProLiant XL290n Gen10 Plus Server
HPE Apollo 2000 Gen10 Plus System
HPE StoreEasy 1860 Storage
Precision 7960 XL Rack
Precision 7920 XL Rack
Precision 7920 Rack
HPE SimpliVity 380 Gen10 Plus
Amazon Linux AMI
Debian Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 12
F5OS
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
SUSE Enterprise Storage
SUSE Linux Enterprise Server 12 SP2 BCL
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Basesystem Module
openSUSE Leap
Ubuntu
Anolis OS
Fedora
VMware Tanzu Application Service for VMs
Isolation Segment
intel-microcode (Ubuntu package)
microcode_ctl
intel-microcode (Debian package)
ucode-intel
ucode-intel-debuginfo
ucode-intel-debugsource
HPE Synergy 480 Gen10 Plus Compute Module
Precision 7960 Rack
PowerSwitch Z9664F-ON
Dell PowerProtect Cyber Recovery
VMware Tanzu Operations Manager
RecoverPoint for VMs
How to mitigate CVE-2023-23908
Install updates from vendor's website.
F5OS - update to 1.8.0
intel-microcode (Ubuntu package) - addressed in versions Ubuntu Pro, 3.20230808.0ubuntu0.20.04.1, 3.20230808.0ubuntu0.22.04.1, 3.20230808.0ubuntu1
HPE Edgeline e920 Server Blade - update to 1.74_07-24-2023
HPE Edgeline e920t Server Blade - update to 1.74_07-24-2023
HPE Edgeline e920d Server Blade - update to 1.74_07-24-2023
HPE ProLiant DL380 Gen10 Plus server - update to 1.80_07-05-2023
HPE ProLiant DL360 Gen10 Plus server - update to 1.80_07-05-2023
HPE ProLiant DL110 Gen10 Plus Telco server - update to 1.80_07-05-2023
HPE Synergy 480 Gen10 Plus Compute Module - update to 1.80_07-05-2023
HPE ProLiant XL220n Gen10 Plus Server - update to 1.80_07-05-2023
HPE StoreEasy 1660 Storage - update to 1.80_07-05-2023
HPE ProLiant DX220n Gen10 Plus server - update to 1.80_07-05-2023
HPE ProLiant DX360 Gen10 Plus server - update to 1.80_07-05-2023
HPE ProLiant DX380 Gen10 Plus server - update to 1.80_07-05-2023
HPE Apollo 4200 Gen10 Plus System - update to 1.80_07-05-2023
HPE ProLiant XL290n Gen10 Plus Server - update to 1.80_07-05-2023
HPE Apollo 2000 Gen10 Plus System - update to 1.80_07-05-2023
HPE StoreEasy 1860 Storage - update to 1.80_07-05-2023
microcode_ctl - update to 2.1-53
microcode_ctl - addressed in versions 2.1-53.2.fc37, 2.1-55.1.fc38
VMware Tanzu Operations Manager - addressed in versions 2.10.61, 3.0.15
Precision 7960 XL Rack - update to 2.19.1
Precision 7960 Rack - update to 2.19.1
Precision 7920 XL Rack - update to 2.19.1
Precision 7920 Rack - update to 2.19.1
PowerSwitch Z9664F-ON - update to 3.54.5.1-6
intel-microcode (Debian package) - addressed in versions 3.20230808.1~deb11u1, 3.20230808.1~deb12u1
RecoverPoint for VMs - update to 6.0.SP1.P1
Dell PowerProtect Cyber Recovery - update to 19.15.0.1
HPE SimpliVity 380 Gen10 Plus - update to 2023_0913
microcode_ctl - update to 20230808-1
ucode-intel - addressed in versions 20230808-13.110.1, 20230808-123.1, 20230808-150100.3.223.1, 20230808-150200.27.1
ucode-intel-debuginfo - addressed in versions 20230808-13.110.1, 20230808-123.1
ucode-intel-debugsource - addressed in versions 20230808-13.110.1, 20230808-123.1
intel-microcode (Ubuntu package) - addressed in versions Ubuntu Pro, 3.20230808.0ubuntu0.20.04.1, 3.20230808.0ubuntu0.22.04.1, 3.20230808.0ubuntu1
HPE Edgeline e920 Server Blade - update to 1.74_07-24-2023
HPE Edgeline e920t Server Blade - update to 1.74_07-24-2023
HPE Edgeline e920d Server Blade - update to 1.74_07-24-2023
HPE ProLiant DL380 Gen10 Plus server - update to 1.80_07-05-2023
HPE ProLiant DL360 Gen10 Plus server - update to 1.80_07-05-2023
HPE ProLiant DL110 Gen10 Plus Telco server - update to 1.80_07-05-2023
HPE Synergy 480 Gen10 Plus Compute Module - update to 1.80_07-05-2023
HPE ProLiant XL220n Gen10 Plus Server - update to 1.80_07-05-2023
HPE StoreEasy 1660 Storage - update to 1.80_07-05-2023
HPE ProLiant DX220n Gen10 Plus server - update to 1.80_07-05-2023
HPE ProLiant DX360 Gen10 Plus server - update to 1.80_07-05-2023
HPE ProLiant DX380 Gen10 Plus server - update to 1.80_07-05-2023
HPE Apollo 4200 Gen10 Plus System - update to 1.80_07-05-2023
HPE ProLiant XL290n Gen10 Plus Server - update to 1.80_07-05-2023
HPE Apollo 2000 Gen10 Plus System - update to 1.80_07-05-2023
HPE StoreEasy 1860 Storage - update to 1.80_07-05-2023
microcode_ctl - update to 2.1-53
microcode_ctl - addressed in versions 2.1-53.2.fc37, 2.1-55.1.fc38
VMware Tanzu Operations Manager - addressed in versions 2.10.61, 3.0.15
Precision 7960 XL Rack - update to 2.19.1
Precision 7960 Rack - update to 2.19.1
Precision 7920 XL Rack - update to 2.19.1
Precision 7920 Rack - update to 2.19.1
PowerSwitch Z9664F-ON - update to 3.54.5.1-6
intel-microcode (Debian package) - addressed in versions 3.20230808.1~deb11u1, 3.20230808.1~deb12u1
RecoverPoint for VMs - update to 6.0.SP1.P1
Dell PowerProtect Cyber Recovery - update to 19.15.0.1
HPE SimpliVity 380 Gen10 Plus - update to 2023_0913
microcode_ctl - update to 20230808-1
ucode-intel - addressed in versions 20230808-13.110.1, 20230808-123.1, 20230808-150100.3.223.1, 20230808-150200.27.1
ucode-intel-debuginfo - addressed in versions 20230808-13.110.1, 20230808-123.1
ucode-intel-debugsource - addressed in versions 20230808-13.110.1, 20230808-123.1
External References
Related Security Bulletins
- Information disclosure in Intel 3rd Gen Intel Xeon Scalable processors
- SUSE update for ucode-intel
- Debian update for intel-microcode
- Ubuntu update for intel-microcode
- SUSE update for ucode-intel
- Fedora 38 update for microcode_ctl
- Fedora 37 update for microcode_ctl
- SUSE update for ucode-intel
- SUSE update for ucode-intel
- VMware Tanzu products update for Intel Microcode
- Privilege escalation in HPE SimpliVity 380 Gen10 Plus
- Multiple vulnerabilities in Dell PowerProtect Cyber Recovery
- F5OS update for Intel Xeon CPU firmware
- Improper access control in Certain HPE Apollo, XL Servers Using Certain Intel Processors
- Improper access control in Certain HPE ProLiant DX Servers Using Certain Intel Processors
- Improper access control in Certain HPE Edgeline Servers Using Certain Intel Processors
- Improper access control in Certain HPE ProLiant DL Servers Using Certain Intel Processors
- Multiple vulnerabilities in Dell RecoverPoint for Virtual Machines
- Multiple vulnerabilities in Dell Precision Rack BIOS
- Amazon Linux AMI update for microcode_ctl
- Anolis OS update for microcode_ctl
- Multiple vulnerabilities in Dell Networking Products
- Improper access control in Certain HPE Synergy Servers Using Certain Intel Processors
- Improper access control in Certain HPE StoreEasy Servers Using Certain Intel Processors