PT-2018-17914 · Hewlett Packard+1 · Hpe Windows Firmware Installer+3

Published

2018-10-25

·

Updated

2020-08-24

·

CVE-2018-7112

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions HPE Windows firmware installer versions prior to the updated versions released in system ROM and HPE Integrated Lights-Out (iLO) releases documented in HPE Security Bulletins: HPESBHF03805, HPESBHF03835, HPESBHF03831
Description The issue allows local disclosure of privileged information. It was resolved in previously provided firmware updates. The updated HPE Windows firmware installer was released in system ROM and HPE Integrated Lights-Out (iLO) releases, which also addressed the original Spectre/Meltdown set of vulnerabilities.
Recommendations For HPE Windows firmware installer versions prior to the updated versions, update to the system ROM or iLO versions described in the HPE Security Bulletins: HPESBHF03805, HPESBHF03835, HPESBHF03831 to resolve the issue. Windows-based systems that have already been updated to the system ROM or iLO versions described in these security bulletins require no further action.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2018-7112

Affected Products

Hp Integrated Lights-Out
Hpe Windows Firmware Installer
Hpe Ilo
Windows