- Community Home
- >
- Servers and Operating Systems
- >
- HPE ProLiant
- >
- ProLiant Servers (ML,DL,SL)
- >
- Re: Critical vulnerability CVE-2021-38578 in serve...
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-23-2024 07:50 AM - last edited on 07-31-2024 05:53 PM by support_s
07-23-2024 07:50 AM - last edited on 07-31-2024 05:53 PM by support_s
Critical vulnerability CVE-2021-38578 in servers with System ROM prior to May 2024
HPE has just published a security bulletin with Severity High, "HPESBHF04671 rev.1 - Certian HPE ProLiant DL/ML/SY/XL and Alletra Servers, Out-of-Bounds Write Vulnerability":
https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=hpesbhf04671en_us
And the corresponding CVE has a score of at least 9.8 Critical:
https://nvd.nist.gov/vuln/detail/CVE-2021-38578
So for DL360 Gen11 servers they must be upgraded to System ROM v2.20_05-27-2024 to patch this vulnerability. But the release notes only marks it with Upgrade Requirement "Recommended". The same goes for the latest BIOS v3.20 for DL360 Gen10.
Question 1: Can someone explain the apparent discrepancy between the criticalitiy levels here?
Question 2: I see Gen11 has a more recent update v2.22 marked as Critical, but that doesn't seem to have anything to do with the CVE-2021-38578 vulnerability. Is that correct?
A CVE score of 9.8 seems pretty serious. The release notes only states "The security vulnerabilities are documented in the CVE report site", but the CVE just says "Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize". That's not very useful.
Question3: Can someone explain or point to any documentation on what attack vectors there are for servers running vulnerable System ROM versions?
- Tags:
- ProLiant Server
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-28-2024 08:34 PM
07-28-2024 08:34 PM
Re: Critical vulnerability CVE-2021-38578 in servers with System ROM prior to May 2024
Hello RuneH,
Thank you for your post.
as mentioned in the revision history :
"This revision of the System ROM includes the mitigation for security vulnerabilities CVE-2023-5678, CVE-2024-0727, CVE-2021-38578 and CVE-2023-45229. The security vulnerabilities are documented in the CVE report site. They are not unique to HPE servers."
If you have further questions on the same , We would suggest you to write to "security@hpe.com" with your queries.
Regards
HPE
I work at HPE
HPE Support Center offers support for your HPE services and products when and how you need it. Get started with HPE Support Center today.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-29-2024 02:13 AM - edited 07-29-2024 02:13 AM
07-29-2024 02:13 AM - edited 07-29-2024 02:13 AM
Re: Critical vulnerability CVE-2021-38578 in servers with System ROM prior to May 2024
No, I would suggest that YOU contact your HPE Security team and invite them here to answer these questions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-29-2024 05:42 PM
07-29-2024 05:42 PM
Re: Critical vulnerability CVE-2021-38578 in servers with System ROM prior to May 2024
Hello RuneH,
That is our internal team.
We request you to log a HPE support case.
https://support.hpe.com/hpesc/public/usageSupport
Regards
HPE
I work at HPE
HPE Support Center offers support for your HPE services and products when and how you need it. Get started with HPE Support Center today.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]
