Arbitrary Code Execution Risk in HPE Servers' Firmware Installers
CVE-2020-7135
7.8HIGH
Key Information:
- Vendor
- HP
- Status
- Vendor
- CVE Published:
- 27 April 2020
Summary
A security vulnerability has been discovered in the disk drive firmware installers present on Hewlett Packard Enterprise servers operating Linux. This issue affects the Supplemental Update / Online ROM Flash Component included in specific releases of the HPE Service Pack for ProLiant (SPP). The vulnerability could allow an attacker with local access to execute arbitrary code via the flawed installer. Users are advised to update to the 2019_03 SPP and subsequent versions of the Supplemental Update / Online ROM Flash Component for Linux (x64) to mitigate this risk.
Affected Version(s)
HPE Business Critical Hard Drives HPG2
HPE NVMe Mixed Use Solid State Drives HPG2
HPE SATA Read Intensive Solid State Drives HPG2
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved