- Community Home
- >
- Servers and Operating Systems
- >
- HPE ProLiant
- >
- ProLiant Servers (ML,DL,SL)
- >
- ML10 Gen9 - latest Intel ME - Vulnerable - as of 2...
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Discussions
Forums
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ā03-21-2018 05:51 AM
ā03-21-2018 05:51 AM
ML10 Gen9 - latest Intel ME - Vulnerable - as of 21 March 2018
Hello
Intel's test (link below) reports that Intel ME 11.6.27.3264 is vulnerable.
https://www.intel.com/content/www/us/en/support/articles/000025619/software.html
However it appears to be the latest available for download from HPE's support.
Is there an update in the pipeline?
Does disabling this in BIOS actually mitigate curent vulnerabilities? (It is disabled but still reports as vulnerable)
Thank you
Paul
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ā03-21-2018 07:32 AM
ā03-21-2018 07:32 AM
Re: ML10 Gen9 - latest Intel ME - Vulnerable - as of 21 March 2018
Hi PaulP-Cambs
Officially of HPE, have this information about vulnerabilyt
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesb3p03767en_us
All Bouletins - https://support.hpe.com/portal/site/hpsc/public/kb/secBullArchive
If necessary more informatio do you can report to more information - https://www.hpe.com/h41268/live/index_e.aspx?qid=11503
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ā03-22-2018 01:04 AM - edited ā03-22-2018 03:19 AM
ā03-22-2018 01:04 AM - edited ā03-22-2018 03:19 AM
Re: ML10 Gen9 - latest Intel ME - Vulnerable - as of 21 March 2018
Hi
That vulnerability appears to relate to the BIOS - I've already patched the BIOS to 1.11.
As far as I can tell the latest Intel ME available is 11.6.27.3264(23 May 2017) here:
Intel's test for Intel ME vulnerabilities returns a result of vulnerable which suggests there should be a patch in HPE's pipeline - Ideally 11.8.50.3425 or higher as per advisory:
https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00086&languageid=en-fr
IntelĀ® XeonĀ® Processor E3-1200 v5 Product Family
Recommended: IntelĀ® ME 11.8.50.3425 or higher
Minimum: IntelĀ® ME 11.8.50.3399
IntelĀ® SPS 4.1.4.054
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ā03-23-2018 03:04 AM
ā03-23-2018 03:04 AM
Re: ML10 Gen9 - latest Intel ME - Vulnerable - as of 21 March 2018
Any idea when it might be made available please?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ā03-26-2018 03:08 AM
ā03-26-2018 03:08 AM
Re: ML10 Gen9 - latest Intel ME - Vulnerable - as of 21 March 2018
As this is still currently being sold - is it being sold with a known vulnerability for which there is an Intel patch that it doesn't have, or is Intel's patch just not being made available existing owners?
Or is there some other mitigation for the vulnerability Intel report?
Makes Lenovo's TS150 look more attractive for my next purchase - while the Lenvo costs more from my reseller, Lenovo have made the patches available, and worth noting also for their legacy TS140 E-1226v3 which I do have and is patched!