<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Critical vulnerability CVE-2021-38578 in servers with System ROM prior to May 2024 in ProLiant Servers (ML,DL,SL)</title>
    <link>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/critical-vulnerability-cve-2021-38578-in-servers-with-system-rom/m-p/7221123#M188096</link>
    <description>&lt;P&gt;HPE has just published a security bulletin with Severity High, "HPESBHF04671 rev.1 - Certian HPE ProLiant DL/ML/SY/XL and Alletra Servers, Out-of-Bounds Write Vulnerability":&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&amp;amp;docId=hpesbhf04671en_us" target="_blank" rel="noopener"&gt;https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&amp;amp;docId=hpesbhf04671en_us&lt;/A&gt;&lt;/P&gt;&lt;P&gt;And the corresponding CVE has a score of at least 9.8 Critical:&lt;/P&gt;&lt;P&gt;&lt;A href="https://nvd.nist.gov/vuln/detail/CVE-2021-38578" target="_blank" rel="noopener"&gt;https://nvd.nist.gov/vuln/detail/CVE-2021-38578&lt;/A&gt;&lt;/P&gt;&lt;P&gt;So for DL360 Gen11 servers they must be upgraded to System ROM v2.20_05-27-2024 to patch this vulnerability. But the release notes only marks it with Upgrade Requirement "Recommended". The same goes for the latest BIOS v3.20 for DL360 Gen10.&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.hpe.com/connect/s/softwaredetails?collectionId=MTX-4f0883f832e649e7&amp;amp;softwareId=MTX_0a6de5de30d241dda1448bc7e4&amp;amp;tab=Fixes" target="_blank" rel="noopener"&gt;https://support.hpe.com/connect/s/softwaredetails?collectionId=MTX-4f0883f832e649e7&amp;amp;softwareId=MTX_0a6de5de30d241dda1448bc7e4&amp;amp;tab=Fixes&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Question 1: Can someone explain the apparent discrepancy between the criticalitiy levels here?&lt;/P&gt;&lt;P&gt;Question 2: I see Gen11 has a more recent update v2.22 marked as Critical, but that doesn't seem to have anything to do with the CVE-2021-38578 vulnerability. Is that correct?&lt;/P&gt;&lt;P&gt;A CVE score of 9.8 seems pretty serious. The release notes only states "The security vulnerabilities are documented in the CVE report site", but the CVE just says "Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize". That's not very useful.&lt;/P&gt;&lt;P&gt;Question3: Can someone explain or point to any documentation on what attack vectors there are for servers running vulnerable System ROM versions?&lt;/P&gt;</description>
    <pubDate>Thu, 01 Aug 2024 00:53:34 GMT</pubDate>
    <dc:creator>RuneH</dc:creator>
    <dc:date>2024-08-01T00:53:34Z</dc:date>
    <item>
      <title>Critical vulnerability CVE-2021-38578 in servers with System ROM prior to May 2024</title>
      <link>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/critical-vulnerability-cve-2021-38578-in-servers-with-system-rom/m-p/7221123#M188096</link>
      <description>&lt;P&gt;HPE has just published a security bulletin with Severity High, "HPESBHF04671 rev.1 - Certian HPE ProLiant DL/ML/SY/XL and Alletra Servers, Out-of-Bounds Write Vulnerability":&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&amp;amp;docId=hpesbhf04671en_us" target="_blank" rel="noopener"&gt;https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&amp;amp;docId=hpesbhf04671en_us&lt;/A&gt;&lt;/P&gt;&lt;P&gt;And the corresponding CVE has a score of at least 9.8 Critical:&lt;/P&gt;&lt;P&gt;&lt;A href="https://nvd.nist.gov/vuln/detail/CVE-2021-38578" target="_blank" rel="noopener"&gt;https://nvd.nist.gov/vuln/detail/CVE-2021-38578&lt;/A&gt;&lt;/P&gt;&lt;P&gt;So for DL360 Gen11 servers they must be upgraded to System ROM v2.20_05-27-2024 to patch this vulnerability. But the release notes only marks it with Upgrade Requirement "Recommended". The same goes for the latest BIOS v3.20 for DL360 Gen10.&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.hpe.com/connect/s/softwaredetails?collectionId=MTX-4f0883f832e649e7&amp;amp;softwareId=MTX_0a6de5de30d241dda1448bc7e4&amp;amp;tab=Fixes" target="_blank" rel="noopener"&gt;https://support.hpe.com/connect/s/softwaredetails?collectionId=MTX-4f0883f832e649e7&amp;amp;softwareId=MTX_0a6de5de30d241dda1448bc7e4&amp;amp;tab=Fixes&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Question 1: Can someone explain the apparent discrepancy between the criticalitiy levels here?&lt;/P&gt;&lt;P&gt;Question 2: I see Gen11 has a more recent update v2.22 marked as Critical, but that doesn't seem to have anything to do with the CVE-2021-38578 vulnerability. Is that correct?&lt;/P&gt;&lt;P&gt;A CVE score of 9.8 seems pretty serious. The release notes only states "The security vulnerabilities are documented in the CVE report site", but the CVE just says "Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize". That's not very useful.&lt;/P&gt;&lt;P&gt;Question3: Can someone explain or point to any documentation on what attack vectors there are for servers running vulnerable System ROM versions?&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2024 00:53:34 GMT</pubDate>
      <guid>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/critical-vulnerability-cve-2021-38578-in-servers-with-system-rom/m-p/7221123#M188096</guid>
      <dc:creator>RuneH</dc:creator>
      <dc:date>2024-08-01T00:53:34Z</dc:date>
    </item>
    <item>
      <title>Re: Critical vulnerability CVE-2021-38578 in servers with System ROM prior to May 2024</title>
      <link>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/critical-vulnerability-cve-2021-38578-in-servers-with-system-rom/m-p/7221433#M188158</link>
      <description>&lt;P dir="auto" style="margin: 0;"&gt;Hello &amp;nbsp;RuneH,&lt;BR /&gt;Thank you for your post.&lt;/P&gt;
&lt;P dir="auto" style="margin: 0;"&gt;as mentioned in the revision history :&lt;BR /&gt;"This revision of the System ROM includes the mitigation for security vulnerabilities CVE-2023-5678, CVE-2024-0727, CVE-2021-38578 and CVE-2023-45229. The security vulnerabilities are documented in the CVE report site. They are not unique to HPE servers."&lt;/P&gt;
&lt;P dir="auto" style="margin: 0;"&gt;If you have further questions on the same , We would suggest you to write to "security@hpe.com" with your queries.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P dir="auto" style="margin: 0;"&gt;Regards&lt;BR /&gt;HPE&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jul 2024 03:34:30 GMT</pubDate>
      <guid>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/critical-vulnerability-cve-2021-38578-in-servers-with-system-rom/m-p/7221433#M188158</guid>
      <dc:creator>Sham82</dc:creator>
      <dc:date>2024-07-29T03:34:30Z</dc:date>
    </item>
    <item>
      <title>Re: Critical vulnerability CVE-2021-38578 in servers with System ROM prior to May 2024</title>
      <link>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/critical-vulnerability-cve-2021-38578-in-servers-with-system-rom/m-p/7221461#M188165</link>
      <description>&lt;P&gt;No, I would suggest that YOU contact your HPE Security team and invite them here to answer these questions &lt;LI-EMOJI id="lia_slightly-smiling-face" title=":slightly_smiling_face:"&gt;&lt;/LI-EMOJI&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jul 2024 09:13:55 GMT</pubDate>
      <guid>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/critical-vulnerability-cve-2021-38578-in-servers-with-system-rom/m-p/7221461#M188165</guid>
      <dc:creator>RuneH</dc:creator>
      <dc:date>2024-07-29T09:13:55Z</dc:date>
    </item>
    <item>
      <title>Re: Critical vulnerability CVE-2021-38578 in servers with System ROM prior to May 2024</title>
      <link>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/critical-vulnerability-cve-2021-38578-in-servers-with-system-rom/m-p/7221535#M188188</link>
      <description>&lt;P dir="auto" style="margin: 0;"&gt;Hello RuneH,&lt;/P&gt;
&lt;P dir="auto" style="margin: 0;"&gt;That is our internal team.&lt;BR /&gt;We request you to log a HPE support case.&lt;BR /&gt;&lt;A href="https://support.hpe.com/hpesc/public/usageSupport" target="_blank"&gt;https://support.hpe.com/hpesc/public/usageSupport&lt;/A&gt;&lt;/P&gt;
&lt;P dir="auto" style="margin: 0;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P dir="auto" style="margin: 0;"&gt;Regards&lt;BR /&gt;HPE&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2024 00:42:08 GMT</pubDate>
      <guid>https://community.hpe.com/t5/proliant-servers-ml-dl-sl/critical-vulnerability-cve-2021-38578-in-servers-with-system-rom/m-p/7221535#M188188</guid>
      <dc:creator>Sham82</dc:creator>
      <dc:date>2024-07-30T00:42:08Z</dc:date>
    </item>
  </channel>
</rss>

