Lucene search

K
hpHP Product Security Response TeamHPSBHF03889
HistoryDec 11, 2023 - 12:00 a.m.

Intel 2023.4 IPU Out-of-Band (OOB) Processor Security Update

2023-12-1100:00:00
HP Product Security Response Team
support.hp.com
18
intel security update
out-of-band processor
hp affected platforms
firmware update
information disclosure

CVSS3

8.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

AI Score

7.4

Confidence

High

EPSS

0

Percentile

5.1%

Intel has informed HP of a potential security vulnerability in some Intel® Processors, which might allow escalation of privilege and/or information disclosure and/or denial of service via local access. Intel is releasing firmware updates to mitigate this potential vulnerability.

Intel has released updates to mitigate the potential vulnerability. HP has identified affected platforms and corresponding SoftPaqs with minimum versions that mitigate the potential vulnerability. See the affected platforms listed below.

Affected configurations

Vulners
Node
hpelite_dragonfly_g2_firmwareRange<01.16.00
OR
hpelite_dragonfly_max_firmwareRange<01.16.00
OR
hpelite_x2_g8_tablet_firmwareRange<01.16.00
OR
hpelitebook_830_g8_firmwareRange<01.16.00
OR
hpelitebook_840_aero_g8_firmwareRange<01.16.00
OR
hpelitebook_840_g8_firmwareRange<01.16.00
OR
hpelitebook_850_g8_firmwareRange<01.16.00
OR
hpelitebook_x360_1030_g8_firmwareRange<01.16.00
OR
hpelitebook_x360_1040_g8_firmwareRange<01.16.00
OR
hpelitebook_x360_830_g8_firmwareRange<01.16.00
OR
hpprobook_430_g8_firmwareRange<01.16.00
OR
hpprobook_440_g8_firmwareRange<01.16.00
OR
hpprobook_450_g8_firmwareRange<01.16.00
OR
hpprobook_630_g8_firmwareRange<01.16.00
OR
hpprobook_640_g8_firmwareRange<01.16.00
OR
hpprobook_650_g8_firmwareRange<01.16.00
OR
hpzbook_firefly_14_inch_g8_mobile_workstation_pc_firmwareRange<01.16.00
OR
hpzbook_firefly_15.6_inch_g8_mobile_workstation_pc_firmwareRange<01.16.00
OR
hpzbook_fury_15.6_inch_g8_mobile_workstation_pc_firmwareRange<01.16.00
OR
hpzbook_fury_17.3_inch_g8_mobile_workstation_pc_firmwareRange<01.16.00
OR
hpzbook_power_15.6_inch_g8_mobile_workstation_pc_firmwareRange<01.16.00
OR
hpzbook_studio_15.6_inch_g8_mobile_workstation_pc_firmwareRange<01.16.00
OR
hpzhan_66_pro_14_g4_notebook_pc_firmwareRange<01.16.00
OR
hpelitedesk_800_g8_desktop_mini_pc_firmwareRange<02.14.00
OR
hpelitedesk_800_g8_small_form_factor_pc_firmwareRange<02.14.00
OR
hpelitedesk_800_g8_tower_pc_firmwareRange<02.14.00
OR
hpelitedesk_880_g8_tower_pc_firmwareRange<02.14.00
OR
hpeliteone_800_g8_24_all-in-one_pc_firmwareRange<02.14.00
OR
hpeliteone_800_g8_27_all-in-one_pc_firmwareRange<02.14.00
OR
hpz1_g8_tower_desktop_pc_firmwareRange<02.14.00
OR
hpengage_go_10_mobile_system_firmwareRange<01.15.00
OR
hpz2_small_form_factor_g8_workstation_firmwareRange<01.06.05
OR
hpz2_small_form_factor_g8_workstation_firmwareRange<01.06.05
OR
hpz2_tower_g8_workstation_firmwareRange<01.06.05
OR
hpz2_tower_g8_workstation_firmwareRange<01.06.05
OR
hp349_g7_firmwareRange<F.32
OR
hp250_g7_firmwareRange<F.47
OR
hp256_g7_firmwareRange<F.47
OR
hp258_g7_firmwareRange<F.47
OR
hpengage_one_all-in-one_system_firmwareRange<F.44
OR
hp205_g4_22_all-in-one_firmwareRange<F.37
OR
hp205_g4_22_all-in-one_firmwareRange<F.41
OR
hp205_g4_22_all-in-one_firmwareRange<F.37
OR
hp205_g4_22_all-in-one_firmwareRange<F.41
OR
hpeliteone_800_g6_24_all-in-one_firmwareRange<F.37
OR
hpeliteone_800_g6_24_all-in-one_firmwareRange<F.41
OR
hpeliteone_800_g6_24_all-in-one_firmwareRange<F.37
OR
hpeliteone_800_g6_24_all-in-one_firmwareRange<F.41
OR
hpeliteone_800_g6_24_all-in-one_firmwareRange<F.37
OR
hpeliteone_800_g6_24_all-in-one_firmwareRange<F.41
OR
hpeliteone_800_g6_27_all-in-one_firmwareRange<F.37
OR
hpeliteone_800_g6_27_all-in-one_firmwareRange<F.41
OR
hpeliteone_1000_g2_34-in_curved_all-in-one_business_firmwareRange<F.20
OR
hphp_envy_te01-2xxx_firmwareRange<F.23
OR
hpeliteone_800_g6_24_all-in-one_firmwareRange<F.20
OR
hpeliteone_800_g6_24_all-in-one_firmwareRange<F.20
OR
hpeliteone_800_g6_27_all-in-one_firmwareRange<F.20
OR
hpeliteone_800_g6_27_all-in-one_firmwareRange<F.20
OR
hphp_pavilion_gaming_tg01-2xxx_firmwareRange<F.23
OR
hphp_pavilion_tp01-2xxx_firmwareRange<F.23
OR
hpomen_gaming_hubRange<F.16
OR
hpomen_gaming_hubRange<F.20
OR
hpomen_gaming_hubRange<F.16
OR
hpomen_gaming_hubRange<F.20
OR
hpomen_gaming_hubRange<F.16
OR
hpomen_gaming_hubRange<F.20
OR
hp280_g5_small_form_factor_firmwareRange<F.32
OR
hp280_g8_microtower_firmwareRange<F.32
OR
hp280_pro_g5_small_form_factor_firmwareRange<F.32
OR
hp280_pro_g5_small_form_factor_firmwareRange<F.32
OR
hp290_g3_small_form_factor_firmwareRange<F.32
VendorProductVersionCPE
hpelite_dragonfly_g2_firmware*cpe:2.3:o:hp:elite_dragonfly_g2_firmware:*:*:*:*:*:*:*:*
hpelite_dragonfly_max_firmware*cpe:2.3:o:hp:elite_dragonfly_max_firmware:*:*:*:*:*:*:*:*
hpelite_x2_g8_tablet_firmware*cpe:2.3:o:hp:elite_x2_g8_tablet_firmware:*:*:*:*:*:*:*:*
hpelitebook_830_g8_firmware*cpe:2.3:o:hp:elitebook_830_g8_firmware:*:*:*:*:*:*:*:*
hpelitebook_840_aero_g8_firmware*cpe:2.3:o:hp:elitebook_840_aero_g8_firmware:*:*:*:*:*:*:*:*
hpelitebook_840_g8_firmware*cpe:2.3:o:hp:elitebook_840_g8_firmware:*:*:*:*:*:*:*:*
hpelitebook_850_g8_firmware*cpe:2.3:o:hp:elitebook_850_g8_firmware:*:*:*:*:*:*:*:*
hpelitebook_x360_1030_g8_firmware*cpe:2.3:o:hp:elitebook_x360_1030_g8_firmware:*:*:*:*:*:*:*:*
hpelitebook_x360_1040_g8_firmware*cpe:2.3:o:hp:elitebook_x360_1040_g8_firmware:*:*:*:*:*:*:*:*
hpelitebook_x360_830_g8_firmware*cpe:2.3:o:hp:elitebook_x360_830_g8_firmware:*:*:*:*:*:*:*:*
Rows per page:
1-10 of 501

CVSS3

8.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

AI Score

7.4

Confidence

High

EPSS

0

Percentile

5.1%