Lucene search

K
hpHP Product Security Response TeamHPSBHF03862
HistoryNov 20, 2023 - 12:00 a.m.

Intel® Virtual RAID on CPU (VROC) August 2023 Security Updates

2023-11-2000:00:00
HP Product Security Response Team
support.hp.com
12
intel
vroc
security
updates
privilege escalation
hp
platforms
software

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.2

Confidence

Low

EPSS

0

Percentile

9.0%

Intel has informed HP of a potential security vulnerability identified in the Intel® Virtual RAID on CPU (VROC) software, which might allow escalation of privilege. Intel is releasing software updates to mitigate the potential vulnerability.

Intel has released updates to mitigate the potential vulnerability. HP has identified affected platforms and corresponding SoftPaqs with minimum versions that mitigate the potential vulnerabilities. See the affected platforms listed below.

Affected configurations

Vulners
Node
hpz4_g4_workstation_\(core-x\)_firmwareRange<8.0.8.1001
OR
hpz4_g4_workstation_\(xeon_w\)_firmwareRange<8.0.8.1001
OR
hpz4_g4_workstation_firmwareRange<8.2.0.1985
OR
hpz6_g4_workstation_firmwareRange<8.0.8.1001
OR
hpz6_g4_workstation_firmwareRange<8.2.0.1985
OR
hpz8_g4_workstation_firmwareRange<8.0.8.1001
OR
hpz8_g4_workstation_firmwareRange<8.2.0.1985
OR
hpz8_g4_workstation_firmwareRange<8.2.0.1985
OR
hpzcentral_4r_workstation_firmwareRange<8.0.8.1001
VendorProductVersionCPE
hpz4_g4_workstation_\(core-x\)_firmware*cpe:2.3:o:hp:z4_g4_workstation_\(core-x\)_firmware:*:*:*:*:*:*:*:*
hpz4_g4_workstation_\(xeon_w\)_firmware*cpe:2.3:o:hp:z4_g4_workstation_\(xeon_w\)_firmware:*:*:*:*:*:*:*:*
hpz4_g4_workstation_firmware*cpe:2.3:o:hp:z4_g4_workstation_firmware:*:*:*:*:*:*:*:*
hpz6_g4_workstation_firmware*cpe:2.3:o:hp:z6_g4_workstation_firmware:*:*:*:*:*:*:*:*
hpz8_g4_workstation_firmware*cpe:2.3:o:hp:z8_g4_workstation_firmware:*:*:*:*:*:*:*:*
hpzcentral_4r_workstation_firmware*cpe:2.3:o:hp:zcentral_4r_workstation_firmware:*:*:*:*:*:*:*:*

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.2

Confidence

Low

EPSS

0

Percentile

9.0%

Related for HPSBHF03862