A local elevation of privilege using physical access security vulnerability was found in HPE Proliant Gen10 Servers using Intel Innovation Engine (IE). This attack requires a physical attack to the server motherboard. To mitigate this issue, ensure your server is always physically secured. HPE will not address this issue in the impacted Gen 10 servers listed. HPE recommends using appropriate physical security methods as a compensating control to disallow an attacker from having physical access to the server main circuit board.

Project Subscriptions

Vendors Products
Apollo 2000 Subscribe
Apollo 2000 Firmware Subscribe
Apollo 4200 Gen10 Subscribe
Apollo 4200 Gen10 Firmware Subscribe
Apollo 4500 Subscribe
Apollo 4500 Firmware Subscribe
Proliant Bl460c Gen10 Subscribe
Proliant Bl460c Gen10 Firmware Subscribe
Proliant Dl120 Gen10 Subscribe
Proliant Dl120 Gen10 Firmware Subscribe
Proliant Dl160 Gen10 Subscribe
Proliant Dl160 Gen10 Firmware Subscribe
Proliant Dl180 Gen10 Subscribe
Proliant Dl180 Gen10 Firmware Subscribe
Proliant Dl360 Gen10 Subscribe
Proliant Dl360 Gen10 Firmware Subscribe
Proliant Dl380 Gen10 Subscribe
Proliant Dl380 Gen10 Firmware Subscribe
Proliant Dl560 Gen10 Subscribe
Proliant Dl560 Gen10 Firmware Subscribe
Proliant Dl580 Gen10 Subscribe
Proliant Dl580 Gen10 Firmware Subscribe
Proliant E910 Subscribe
Proliant E910 Firmware Subscribe
Proliant Ml110 Gen10 Subscribe
Proliant Ml110 Gen10 Firmware Subscribe
Proliant Ml350 Gen10 Subscribe
Proliant Ml350 Gen10 Firmware Subscribe
Proliant Xl170r Gen10 Subscribe
Proliant Xl170r Gen10 Firmware Subscribe
Proliant Xl190r Gen10 Subscribe
Proliant Xl190r Gen10 Firmware Subscribe
Proliant Xl230k Gen10 Subscribe
Proliant Xl230k Gen10 Firmware Subscribe
Proliant Xl270d Gen10 Subscribe
Proliant Xl270d Gen10 Firmware Subscribe
Proliant Xl450 Gen10 Subscribe
Proliant Xl450 Gen10 Firmware Subscribe
Synergy 480 Gen10 Subscribe
Synergy 480 Gen10 Firmware Subscribe
Synergy 660 Gen10 Subscribe
Synergy 660 Gen10 Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2020-28341 A local elevation of privilege using physical access security vulnerability was found in HPE Proliant Gen10 Servers using Intel Innovation Engine (IE). This attack requires a physical attack to the server motherboard. To mitigate this issue, ensure your server is always physically secured. HPE will not address this issue in the impacted Gen 10 servers listed. HPE recommends using appropriate physical security methods as a compensating control to disallow an attacker from having physical access to the server main circuit board.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2024-08-04T09:25:48.465Z

Reserved: 2020-01-16T00:00:00

Link: CVE-2020-7207

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-11-05T21:15:13.063

Modified: 2024-11-21T05:36:49.840

Link: CVE-2020-7207

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses