<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Intel CPU vunerabilities Proliant DL360 in Servers - General</title>
    <link>https://community.hpe.com/t5/servers-general/intel-cpu-vunerabilities-proliant-dl360/m-p/7169533#M17094</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;For example in DL360 Gen10, these&amp;nbsp;vulnerability is addressed in the form of BIOS update.&lt;BR /&gt;Please refer to &lt;A href="https://support.hpe.com/connect/s/softwaredetails?language=en_US&amp;amp;softwareId=MTX_208454153dfb46ff9c6b0492a5&amp;amp;tab=revisionHistory" target="_blank" rel="noopener"&gt;Revision History&lt;/A&gt; for a list of fixes.&lt;/P&gt;&lt;P&gt;Thank You!&lt;/P&gt;&lt;P&gt;I work with HPE but opinions expressed here are mine.&lt;BR /&gt;&lt;A href="https://support.hpe.com/connect/s/search?language=en_US#t=Videos&amp;amp;sort=%40hpescuniversaldate%20descending&amp;amp;layout=card&amp;amp;numberOfResults=100" target="_blank"&gt;Recent Support Video Releases&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 30 Jun 2022 07:20:13 GMT</pubDate>
    <dc:creator>Suman_1978</dc:creator>
    <dc:date>2022-06-30T07:20:13Z</dc:date>
    <item>
      <title>Intel CPU vunerabilities Proliant DL360</title>
      <link>https://community.hpe.com/t5/servers-general/intel-cpu-vunerabilities-proliant-dl360/m-p/7169451#M17089</link>
      <description>&lt;P&gt;I was made aware of two updates Intel released for their CPU's to address two vunerabilities.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00645.html" target="_blank"&gt;https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00645.html&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00615.html" target="_blank"&gt;https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00615.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I found a few of our servers (mostly the Proliant DL360 models of various generations) have their CPU listed as affected for both vunerabilities, and all are mentioned as fixed in software: Mitigation implemented in software, and software updates needed to enable mitigation&lt;/P&gt;&lt;P&gt;The DL360 G10 however also mentions a microcode update being required.&lt;/P&gt;&lt;P&gt;I am however unsure what 'software' update (or even microcode update) would actually mitigate these vunerabilities. Does anyone have any insight?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 05:37:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/servers-general/intel-cpu-vunerabilities-proliant-dl360/m-p/7169451#M17089</guid>
      <dc:creator>Neko-</dc:creator>
      <dc:date>2022-07-05T05:37:21Z</dc:date>
    </item>
    <item>
      <title>Re: Intel CPU vunerabilities Proliant DL360</title>
      <link>https://community.hpe.com/t5/servers-general/intel-cpu-vunerabilities-proliant-dl360/m-p/7169533#M17094</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;For example in DL360 Gen10, these&amp;nbsp;vulnerability is addressed in the form of BIOS update.&lt;BR /&gt;Please refer to &lt;A href="https://support.hpe.com/connect/s/softwaredetails?language=en_US&amp;amp;softwareId=MTX_208454153dfb46ff9c6b0492a5&amp;amp;tab=revisionHistory" target="_blank" rel="noopener"&gt;Revision History&lt;/A&gt; for a list of fixes.&lt;/P&gt;&lt;P&gt;Thank You!&lt;/P&gt;&lt;P&gt;I work with HPE but opinions expressed here are mine.&lt;BR /&gt;&lt;A href="https://support.hpe.com/connect/s/search?language=en_US#t=Videos&amp;amp;sort=%40hpescuniversaldate%20descending&amp;amp;layout=card&amp;amp;numberOfResults=100" target="_blank"&gt;Recent Support Video Releases&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jun 2022 07:20:13 GMT</pubDate>
      <guid>https://community.hpe.com/t5/servers-general/intel-cpu-vunerabilities-proliant-dl360/m-p/7169533#M17094</guid>
      <dc:creator>Suman_1978</dc:creator>
      <dc:date>2022-06-30T07:20:13Z</dc:date>
    </item>
    <item>
      <title>Re: Intel CPU vunerabilities Proliant DL360</title>
      <link>https://community.hpe.com/t5/servers-general/intel-cpu-vunerabilities-proliant-dl360/m-p/7169563#M17096</link>
      <description>&lt;P&gt;The intel documentation refers to BOTH software and microcode updates being needed for the DL360 G10. So just updating the BIOS wouldn't sort the problem fully. That still leaves the software component.&amp;nbsp;&lt;/P&gt;&lt;P&gt;And since that software component is the ONLY bit applicable to our DL360 G9 servers, that still leaves me with a question on how to sort this vunerability on all systems.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jun 2022 10:00:15 GMT</pubDate>
      <guid>https://community.hpe.com/t5/servers-general/intel-cpu-vunerabilities-proliant-dl360/m-p/7169563#M17096</guid>
      <dc:creator>Neko-</dc:creator>
      <dc:date>2022-06-30T10:00:15Z</dc:date>
    </item>
    <item>
      <title>Re: Intel CPU vunerabilities Proliant DL360</title>
      <link>https://community.hpe.com/t5/servers-general/intel-cpu-vunerabilities-proliant-dl360/m-p/7169751#M17103</link>
      <description>&lt;P&gt;Seems HPE started a case for this (according to a PM I got)...&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Curious how this is going to proceed &lt;LI-EMOJI id="lia_slightly-smiling-face" title=":slightly_smiling_face:"&gt;&lt;/LI-EMOJI&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jul 2022 07:38:39 GMT</pubDate>
      <guid>https://community.hpe.com/t5/servers-general/intel-cpu-vunerabilities-proliant-dl360/m-p/7169751#M17103</guid>
      <dc:creator>Neko-</dc:creator>
      <dc:date>2022-07-04T07:38:39Z</dc:date>
    </item>
    <item>
      <title>Re: Intel CPU vunerabilities Proliant DL360</title>
      <link>https://community.hpe.com/t5/servers-general/intel-cpu-vunerabilities-proliant-dl360/m-p/7169800#M17105</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;Please find the below details.&lt;/P&gt;&lt;P&gt;INTEL-SA-00615 - &lt;A href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00615.html" target="_blank"&gt;https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00615.html&lt;/A&gt;&lt;BR /&gt;Affected BIOS version of DL360 Gen10 Prior to 2.66_05_17_2022&lt;/P&gt;&lt;P&gt;Answer:&lt;BR /&gt;Please find the document for vulnerability with CVE-2022-21123&lt;BR /&gt;&lt;A href="https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&amp;amp;docId=hpesbhf04320en_us" target="_blank"&gt;https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&amp;amp;docId=hpesbhf04320en_us&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Actions: Upgrade the BIOS to 2.66 (latest available)&lt;/P&gt;&lt;P&gt;Download Link: &lt;A href="https://support.hpe.com/connect/s/softwaredetails?softwareId=MTX_fbd553aa2bd344f3b83abf7e10&amp;amp;language=en_US&amp;amp;tab=releaseNotes" target="_blank"&gt;https://support.hpe.com/connect/s/softwaredetails?softwareId=MTX_fbd553aa2bd344f3b83abf7e10&amp;amp;language=en_US&amp;amp;tab=releaseNotes&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;In regard to CVE-2022-21180, I request you to raise a ticket with HPE Support with the below details as it requires further investigation. We have not found any document related to this vulnerability.&lt;/P&gt;&lt;P&gt;1. Serial number of the server on which this Vulnerability (CVE-2022-21180) is reported.&lt;BR /&gt;2. Scanner name and scan report.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 04:05:15 GMT</pubDate>
      <guid>https://community.hpe.com/t5/servers-general/intel-cpu-vunerabilities-proliant-dl360/m-p/7169800#M17105</guid>
      <dc:creator>Kashyap02</dc:creator>
      <dc:date>2022-07-05T04:05:15Z</dc:date>
    </item>
    <item>
      <title>Re: Intel CPU vunerabilities Proliant DL360</title>
      <link>https://community.hpe.com/t5/servers-general/intel-cpu-vunerabilities-proliant-dl360/m-p/7169814#M17107</link>
      <description>&lt;P&gt;&lt;a href="https://community.hpe.com/t5/user/viewprofilepage/user-id/1929236"&gt;@Kashyap02&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BIOS noted... That _should_ be scheduled for the oncoming night on the DL360G10. (going from 2.50 to 2.66)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Still leaves the question what software Intel is referring to, to remedy the vunerability... but I'm suspecting that would likely be a question outside of HP's scope...&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2022 07:29:16 GMT</pubDate>
      <guid>https://community.hpe.com/t5/servers-general/intel-cpu-vunerabilities-proliant-dl360/m-p/7169814#M17107</guid>
      <dc:creator>Neko-</dc:creator>
      <dc:date>2022-07-06T07:29:16Z</dc:date>
    </item>
  </channel>
</rss>

