PT-2020-19464 · Gnu+1 · Grub2+3

Published

2020-07-30

·

Updated

2021-07-21

·

CVE-2020-7205

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions HPE Intelligent Provisioning, Service Pack for ProLiant, and HPE Scripting ToolKit (affected versions not specified)
Description A potential security issue has been identified that could allow arbitrary code execution during the boot process. This issue is related to using insmod in GRUB2 in the specific impacted HPE products. HPE has addressed this issue by providing software updates and mitigation information. The updates include a GRUB2 patch and an update to the Forbidden Signature Database (DBX), which will prevent older versions of the affected products from booting with Secure Boot enabled.
Recommendations For HPE Intelligent Provisioning, Service Pack for ProLiant, and HPE Scripting ToolKit, update to the latest version that includes the GRUB2 patch to resolve the issue. Use the provided standalone DBX update tool to update the Forbidden Signature Database (DBX) from within the operating system, which mitigates the GRUB2 issue with insmod enabled.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-7205

Affected Products

Grub2
Hp Intelligent Provisioning
Hpe Scripting Toolkit
Hpe Service Pack For Proliant