- Community Home
- >
- Software
- >
- HPE OneView
- >
- Oneview 6.60.05 , fix for CVE-2023-30909
Categories
Company
Local Language
Forums
Discussions
Knowledge Base
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Knowledge Base
Forums
Discussions
- Cloud Mentoring and Education
- Software - General
- HPE OneView
- HPE Ezmeral Software platform
- HPE OpsRamp
Knowledge Base
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-27-2023 03:01 AM - last edited on 09-27-2023 09:02 AM by support_s
09-27-2023 03:01 AM - last edited on 09-27-2023 09:02 AM by support_s
Hi,
in HPESBGN04538 ( https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=hpesbgn04538en_us )
it is stated that Oneview releases "Prior to v8.30.01" are affected.
In my understanding this means release 6.60.05 is also affected.
HPESBGN04530 states Release 6.60.05 has a fix for CVE-2023-30908, but none for CVE-2023-30909.
(link to bulletin https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=hpesbgn04530en_us )
So i assume, Oneview 6.60.05 is currently vulnerable in regards of CVE-2023-30909.
When can we expect a Patch to fix this issue?
Thanks
Nico
Solved! Go to Solution.
- Tags:
- bios
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-27-2023 08:54 AM
09-27-2023 08:54 AM
SolutionSo i assume, Oneview 6.60.05 is currently vulnerable in regards of CVE-2023-30909.
The CA details are a bit confusing, and we are updating it to be a bit more helpful.
it is stated that Oneview releases "Prior to v8.30.01" are affected.
In my understanding this means release 6.60.05 is also affected.
6.60.05 contains the fixes for CVE-2023-30908 and CVE-2023-30909. The wording "Prior to" should imply 8.30.00 and nothing before that specific release. As we continously release OneView updates, they will include bug and security fixes along with new features (except for the 6.60.xx releases as those are only bug and security fixes.)
The current versions that address both CVE-2023-30908 and CVE-2023-30909 are:
- 6.60.05
- 8.30.01
- 8.50
We are working on re-releasing 8.00.00 and 8.40.00 with 8.00.01 and 8.40.01
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-27-2023 10:03 AM
09-27-2023 10:03 AM
Re: Oneview 6.60.05 , fix for CVE-2023-30909
Thanks Chris for your quick response and the clarification!
I am glad it is already resolved in 6.60.05.
CU
Nico
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-27-2023 09:28 PM
09-27-2023 09:28 PM