Description
A potential security vulnerability has been identified in HPE Intelligent Provisioning, Service Pack for ProLiant, and HPE Scripting ToolKit. The vulnerability could be locally exploited to allow arbitrary code execution during the boot process. **Note:** This vulnerability is related to using insmod in GRUB2 in the specific impacted HPE product and HPE is addressing this issue. HPE has made the following software updates and mitigation information to resolve the vulnerability in Intelligent Provisioning, Service Pack for ProLiant, and HPE Scripting ToolKit. HPE provided latest Intelligent Provisioning, Service Pack for ProLiant, and HPE Scripting Toolkit which includes the GRUB2 patch to resolve this vulnerability. These new boot images will update GRUB2 and the Forbidden Signature Database (DBX). After the DBX is updated, users will not be able to boot to the older IP, SPP or Scripting ToolKit with Secure Boot enabled. HPE have provided a standalone DBX update tool to work with Microsoft Windows, and supported Linux Operating Systems. These tools can be used to update the Forbidden Signature Database (DBX) from within the OS. **Note:** This DBX update mitigates the GRUB2 issue with insmod enabled, and the "Boot Hole" issue for HPE signed GRUB2 applications.
Published: 2020-07-30
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2020-28339 A potential security vulnerability has been identified in HPE Intelligent Provisioning, Service Pack for ProLiant, and HPE Scripting ToolKit. The vulnerability could be locally exploited to allow arbitrary code execution during the boot process. **Note:** This vulnerability is related to using insmod in GRUB2 in the specific impacted HPE product and HPE is addressing this issue. HPE has made the following software updates and mitigation information to resolve the vulnerability in Intelligent Provisioning, Service Pack for ProLiant, and HPE Scripting ToolKit. HPE provided latest Intelligent Provisioning, Service Pack for ProLiant, and HPE Scripting Toolkit which includes the GRUB2 patch to resolve this vulnerability. These new boot images will update GRUB2 and the Forbidden Signature Database (DBX). After the DBX is updated, users will not be able to boot to the older IP, SPP or Scripting ToolKit with Secure Boot enabled. HPE have provided a standalone DBX update tool to work with Microsoft Windows, and supported Linux Operating Systems. These tools can be used to update the Forbidden Signature Database (DBX) from within the OS. **Note:** This DBX update mitigates the GRUB2 issue with insmod enabled, and the "Boot Hole" issue for HPE signed GRUB2 applications.
History

No history.

Subscriptions

Hpe Apollo 2000 Gen10 Plus System Apollo 4200 Gen10 Server Apollo 4200 Gen9 Server Apollo 4510 Gen10 System Apollo 4520 Chassis Apollo 6500 Gen10 System Cloudline Cl2100 Gen10 Server Cloudline Cl2200 Gen10 Server Cloudline Cl2600 Gen10 Server Cloudline Cl2800 Gen10 Server Cloudline Cl3100 Gen10 Server Cloudline Cl3100 Gen9 Server Cloudline Cl3150 Gen10 Server Cloudline Cl4100 Gen10 Server Cloudline Cl5200 Gen9 Server Cloudline Cl5800 Gen9 Server Intelligent Provisioning Proliant Bl460c Gen10 Server Blade Proliant Bl460c Gen8 Blade Server Proliant Bl460c Gen9 Server Blade Proliant Bl660c Gen8 Blade Server Proliant Bl660c Gen9 Server Blade Proliant Dl120 Gen10 Server Proliant Dl120 Gen9 Server Proliant Dl160 Gen10 Server Proliant Dl160 Gen8 Server Proliant Dl160 Gen9 Server Proliant Dl180 Gen10 Server Proliant Dl180 Gen9 Server Proliant Dl20 Gen10 Server Proliant Dl20 Gen9 Server Proliant Dl325 Gen10 Server Proliant Dl360 Gen10 Server Proliant Dl360 Gen9 Server Proliant Dl360e Gen8 Server Proliant Dl360p Gen8 Server Proliant Dl380 Gen10 Server Proliant Dl380 Gen9 Server Proliant Dl380e Gen8 Server Proliant Dl380p Gen8 Server Proliant Dl385 Gen10 Server Proliant Dl385p Gen8 Server Proliant Dl388 Gen9 Server Proliant Dl560 Gen10 Server Proliant Dl560 Gen8 Server Proliant Dl560 Gen9 Server Proliant Dl580 Gen10 Server Proliant Dl580 Gen8 Server Proliant Dl580 Gen9 Server Proliant Dl60 Gen9 Server Proliant Dl80 Gen9 Server Proliant Dx170r Gen10 Server Proliant Dx190r Gen10 Server Proliant Dx360 Gen10 Server Proliant Dx380 Gen10 Server Proliant Dx385 Gen10 Plus Server Proliant Dx4200 Gen10 Server Proliant Dx560 Gen10 Server Proliant E910 Server Blade Proliant M510 Server Cartridge Proliant M710x-l Server Blade Proliant M710x Server Blade Proliant M750 Server Blade Proliant Microserver Gen10 Proliant Microserver Gen10 Plus Proliant Ml10 Gen9 Server Proliant Ml110 Gen10 Server Proliant Ml110 Gen9 Server Proliant Ml150 Gen9 Server Proliant Ml30 Gen10 Server Proliant Ml30 Gen9 Server Proliant Ml310e Gen8 Server Proliant Ml350 Gen10 Server Proliant Ml350 Gen9 Server Proliant Ml350e Gen8 Server Proliant Ml350p Gen8 Server Proliant Se2160w Gen9 Server Proliant Sl230s Gen8 Server Proliant Sl250s Gen8 Server Proliant Sl270s Gen8 Server Proliant Sl4540 Gen8 Server Proliant Ws460c Gen8 Graphics Server Blade Proliant Ws460c Gen9 Graphics Server Blade Proliant Xl170r Gen10 Server Proliant Xl170r Gen9 Server Proliant Xl190r Gen10 Server Proliant Xl190r Gen9 Server Proliant Xl220n Gen10 Plus Server Proliant Xl230a Gen9 Server Proliant Xl230k Gen10 Server Proliant Xl250a Gen9 Server Proliant Xl260a Gen9 Server Proliant Xl270d Gen10 Server Proliant Xl270d Gen9 Server Proliant Xl270d Gen9 Special Server Proliant Xl290n Gen10 Plus Server Proliant Xl2x260w Gen10 Server Proliant Xl450 Gen10 Server Proliant Xl450 Gen9 Server Proliant Xl730f Gen9 Server Proliant Xl740f Gen9 Server Proliant Xl750f Gen9 Server Proliant Xl925g Gen10 Plus 1u 4-node Configure-to-order Server Service Pack For Proliant Simplivity 2600 Gen10 Simplivity 325 Gen10 Simplivity 380 Gen10 Smartstart Scripting Toolkit Storeeasy 1000 Storage Gen10 Storeeasy 1000 Storage Gen9 Synergy 480 Gen10 Compute Module Synergy 480 Gen10 Plus Compute Module Synergy 480 Gen9 Compute Module Synergy 620 Gen9 Compute Module Synergy 660 Gen10 Compute Module Synergy 660 Gen9 Compute Module Synergy 680 Gen9 Compute Module Synergy D3940 Storage Module
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2024-08-04T09:25:48.501Z

Reserved: 2020-01-16T00:00:00.000Z

Link: CVE-2020-7205

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-07-30T18:15:11.737

Modified: 2024-11-21T05:36:49.470

Link: CVE-2020-7205

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses