PT-2018-17914 · Hewlett Packard+1 · Hpe Windows Firmware Installer+3
Published
2018-10-25
·
Updated
2020-08-24
·
CVE-2018-7112
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
HPE Windows firmware installer versions prior to the updated versions released in system ROM and HPE Integrated Lights-Out (iLO) releases documented in HPE Security Bulletins: HPESBHF03805, HPESBHF03835, HPESBHF03831
Description
The issue allows local disclosure of privileged information. It was resolved in previously provided firmware updates. The updated HPE Windows firmware installer was released in system ROM and HPE Integrated Lights-Out (iLO) releases, which also addressed the original Spectre/Meltdown set of vulnerabilities.
Recommendations
For HPE Windows firmware installer versions prior to the updated versions, update to the system ROM or iLO versions described in the HPE Security Bulletins: HPESBHF03805, HPESBHF03835, HPESBHF03831 to resolve the issue.
Windows-based systems that have already been updated to the system ROM or iLO versions described in these security bulletins require no further action.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hp Integrated Lights-Out
Hpe Windows Firmware Installer
Hpe Ilo
Windows