CVE-2018-7112

UnknownEPSS 0.67%

Last modified

CVE-2018-7112 is a vulnerability of currently unknown severity. The HPE-provided Windows firmware installer for certain Gen9, Gen8, G7,and G6 HPE servers allows local disclosure of privileged information. This issue was resolved in previously provided firmware updates as follows. EPSS estimates a 0.67% chance of exploitation in the next 30 days.

Description

The HPE-provided Windows firmware installer for certain Gen9, Gen8, G7,and G6 HPE servers allows local disclosure of privileged information. This issue was resolved in previously provided firmware updates as follows. The HPE Windows firmware installer was updated in the system ROM updates which also addressed the original Spectre/Meltdown set of vulnerabilities. At that time, the Windows firmware installer was also updated in the versions of HPE Integrated Lights-Out 2, 3, and 4 (iLO 2, 3, and 4) listed in the security bulletin. The updated HPE Windows firmware installer was released in the system ROM and HPE Integrated Lights-Out (iLO) releases documented in earlier HPE Security Bulletins: HPESBHF03805, HPESBHF03835, HPESBHF03831. Windows-based systems that have already been updated to the system ROM or iLO versions described in these security bulletins require no further action.

Metrics

EPSS Probability
0.67%

47.2th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
HpIntegrated Lights-Out 2 Firmware< 2.33
HpIntegrated Lights-Out 3 Firmware< 1.90
HpIntegrated Lights-Out 4 Firmware< 2.60
HpProliant Xl750f Gen9 Server Firmware< 2.56_01-22-2018
HpProliant Xl740f Gen9 Server Firmware< 2.56_01-22-2018
HpProliant Xl730f Gen9 Server Firmware< 2.56_01-22-2018
HpProliant Xl450 Gen9 Server Firmware< 2.56_01-22-2018
HpProliant Xl270d Gen9 Server Firmware< 2.56_01-22-2018
HpProliant Xl270d Gen9 Accelerator Tray Firmware< 2.56_01-22-2018
HpProliant Xl260a Gen9 Server Firmware< 1.60_01-22-2018
HpProliant Xl250a Gen9 Server Firmware< 2.56_01-22-2018
HpProliant Xl230a Gen9 Server Firmware< 2.56_01-22-2018
HpProliant Xl190r Gen9 Server Firmware< 2.56_01-22-2018
HpProliant Xl170r Gen9 Server Firmware< 2.56_01-22-2018
HpProliant Dl560 Gen9 Server Firmware< 2.56_01-22-2018
HpProliant Dl380 Gen9 Server Firmware< 2.56_01-22-2018
HpProliant Dl360 Gen9 Server Firmware< 2.56_01-22-2018
HpProliant Dl180 Gen9 Server Firmware< 2.56_01-22-2018
HpProliant Dl160 Gen9 Server Firmware< 2.56_01-22-2018
HpProliant Dl120 Gen9 Server Firmware< 2.56_01-22-2018
HpProliant Dl80 Gen9 Server Firmware< 2.56_01-22-2018
HpProliant Dl60 Gen9 Server Firmware< 2.56_01-22-2018
HpProliant Dl20 Gen9 Server Firmware< 2.56_01-22-2018
HpProliant Ml350 Gen9 Server Firmware< 2.56_01-22-2018
HpProliant Ml150 Gen9 Server Firmware< 2.56_01-22-2018
HpProliant Ml110 Gen9 Server Firmware< 2.56_01-22-2018
HpProliant Ml30 Gen9 Server Firmware< 2.56_01-22-2018
HpProliant Ml10 Gen9 Server Firmware< 2018.01.22
HpProliant Bl660c Gen9 Server Firmware< 2.56_01-22-2018
HpProliant Bl460c Gen9 Server Blade Firmware< 2.56_01-22-2018
HpProliant Ws460c Gen9 Workstation Firmware< 2.56_01-22-2018
HpProliant Dl380e Gen8 Server Firmware< 2018.01.22
HpProliant Dl360p Gen8 Server Firmware< 2018.01.22
HpProliant Dl360e Gen8 Server Firmware< 2018.01.22
HpProliant Dl320e Gen8 Server Firmware< 2018.01.22
HpProliant Dl320e Gen8 V2 Server Firmware< 2018.01.22
HpProliant Dl160 Gen8 Server Firmware< 2018.01.22
HpProliant Sl250s Gen8 Server Firmware< 2018.01.22
HpProliant Sl210t Gen8 Server Firmware< 2018.01.22
HpProliant Bl660c Gen8 Server Blade Firmware< 2018.01.22
HpProliant Bl465c Gen8 \(Amd\) Firmware< 2018.03.14
HpProliant Bl460c Gen8 Server Blade Firmware< 2018.01.22
HpProliant Bl420c Gen8 Server Firmware< 2018.01.22
HpProliant Sl4540 Gen8 1 Node Server Firmware< 2018.01.22
HpProliant Sl270s Gen8 Server Firmware< 2018.01.22
HpProliant Dl580 Gen8 Server Firmware< 2.00_02-22-2018
HpProliant Dl560 Gen8 Server Firmware< 2018.01.22
HpProliant Dl380p Gen8 Server Firmware< 2018.01.22
HpProliant Dl385p Gen8 \(Amd\) Firmware< 2018.03.14
HpProliant Ml350e Gen8 V2 Server Firmware< 2018.01.22

Showing 50 of 101 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2018-7112?
The HPE-provided Windows firmware installer for certain Gen9, Gen8, G7,and G6 HPE servers allows local disclosure of privileged information. This issue was resolved in previously provided firmware updates as follows. The HPE Windows firmware installer was updated in the system ROM updates which also addressed the original Spectre/Meltdown set of vulnerabilities. At that time, the Windows firmware installer was also updated in the versions of HPE Integrated Lights-Out 2, 3, and 4 (iLO 2, 3, and 4) listed in the security bulletin. The updated HPE Windows firmware installer was released in the system ROM and HPE Integrated Lights-Out (iLO) releases documented in earlier HPE Security Bulletins: HPESBHF03805, HPESBHF03835, HPESBHF03831. Windows-based systems that have already been updated to the system ROM or iLO versions described in these security bulletins require no further action.
How severe is CVE-2018-7112?
Severity scoring for CVE-2018-7112 is pending analysis. The EPSS model estimates a 0.67% probability of exploitation in the next 30 days.
How do I fix CVE-2018-7112?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2018-7112?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST