- Community Home
- >
- Servers and Operating Systems
- >
- HPE ProLiant
- >
- ProLiant Servers (ML,DL,SL)
- >
- Spectre and Meltdown
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО01-06-2018 08:01 AM
тАО01-06-2018 08:01 AM
Spectre and Meltdown
The world is going to want to know from HP, where the firmware and BIOS updates are that mitigate the Spectre and Meltdown exploits on 5 years plus of server models.
We need to hear from you HP and soon.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО01-06-2018 02:40 PM
тАО01-06-2018 02:40 PM
Re: Spectre and Meltdown
Don't you think that such important subject already deserved an entire HPE Blog entry?
Here one to start with:
https://community.hpe.com/t5/Servers-The-Right-Compute/Resources-to-help-mitigate-Speculative-Execution-vulnerability/ba-p/6992955
I'm not an HPE Employee

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО01-06-2018 03:01 PM
тАО01-06-2018 03:01 PM
Re: Spectre and Meltdown
Thanks for the link.
So, no support for machines older than G8?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО01-08-2018 03:23 AM
тАО01-08-2018 03:23 AM
Re: Spectre and Meltdown
We have an array of HP Proliant DL360 and 380 servers all G7 and below will these never receive the ROM updates?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО01-08-2018 06:19 AM
тАО01-08-2018 06:19 AM
Re: Spectre and Meltdown
I don't think, that HP can afford to let the G7 and even the G6 Servers unpatched - this would be outrageous and forcing many many customers away from HP since G6 and G7 Servers are widely spread in the field out there. Also I don't think that it's legal to require an entitlement for a security issue like that - this already feels wrong...
Let's wait that HP will do once the patches came out.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО01-08-2018 08:56 AM
тАО01-08-2018 08:56 AM
Re: Spectre and Meltdown
@JuniperChris929 wrote:I don't think, that HP can afford to let the G7 and even the G6 Servers unpatched - this would be outrageous and forcing many many customers away from HP since G6 and G7 Servers are widely spread in the field out there. Also I don't think that it's legal to require an entitlement for a security issue like that - this already feels wrong...
Let's wait that HP will do once the patches came out.
While I dont' have answers to your G6 and G7 questions, I can state that security fixes do not require an entitlement to download. This is clearly stated in the document : HPE ProLiant Servers Firmware Access Update This is the document normally displayed when you try to access a locked download
" тАЬCriticalтАЭ related firmware updates (addressing safety and security fixes) will be made available to all ProLiant customers outside of a warranty or support contract and are governed by "customer terms of use".
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО01-08-2018 09:01 AM
тАО01-08-2018 09:01 AM
Re: Spectre and Meltdown
>> Also I don't think that it's legal to require an entitlement for a security issue like that
For all the BIOS (microcode) updates released so far you don't need an entitlement, because they are "critical".
Hope this helps!
Regards
Torsten.
__________________________________________________
There are only 10 types of people in the world -
those who understand binary, and those who don't.
__________________________________________________
No support by private messages. Please ask the forum!
If you feel this was helpful please click the KUDOS! thumb below!

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО01-08-2018 09:25 AM
тАО01-08-2018 09:25 AM
Re: Spectre and Meltdown
Hi.
i already installed Bios 2.54 on my Dl380 Gen9 and MS Patches but i still get a negative response from the "Speculation Control Validation PowerShell Script"
this is what i did:
- apply Regestry keys (QualityCompat, FeatureSettingsOverride and FeatureSettingsOverrideMask)
- install Bios 2.54
- install MS Patches (KB4056898 + KB4056568)
- reboot
seems to me as if there is someting wrong... Bios update or Script!? what is your experience?
here is the output from the script:
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО01-08-2018 02:50 PM - edited тАО01-08-2018 02:53 PM
тАО01-08-2018 02:50 PM - edited тАО01-08-2018 02:53 PM
Re: Spectre and Meltdown
Did you try a second reboot?
I noticed during applying firmware updates to our Gen9 servers that a second reboot was required.
I believe the correct process is to do firmware first then reboot, then apply OS updates and reboot again.
I tried a couple of times to install both the firmware and OS updates at the same time and do a single reboot but it never worked, always needed the second reboot.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО01-09-2018 01:42 AM
тАО01-09-2018 01:42 AM
Re: Spectre and Meltdown
n1! second reboot did the trick! thx!
next problem are our ESX Servers on Dl380 gen9 (latest 6.5201712101 and 6.0 201711101) also with Bios 2.54 (more times rebootet).
all VMs running telling that a Bios update is needed! (HW version 11 used Speculation Control Validation PowerShell Script)
what to do?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО01-09-2018 08:56 AM
тАО01-09-2018 08:56 AM
Re: Spectre and Meltdown
We are in the same boat. DL360 Gen9's running 2.54 bios, VMware esxi 6.5 with the patches applied, and VM-guest Windows OS' with the Patches/Registry entries, rebooted multiple times.
In-guest Get-SpeculationControlSettings gives the following
CVE-2017-5754 is all green
CVE-2017-5715 shows no hardware support. Recommendation is to "Install BIOS/firmware update provided ...".
I tried upgrading a VM to hardware v13, no change.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО01-09-2018 09:16 AM
тАО01-09-2018 09:16 AM
Re: Spectre and Meltdown
Vmware released new Patches:
here is the microcode we have bben waiting for...
https://esxi-patches.v-front.de/ESXi-6.0.0.html
https://esxi-patches.v-front.de/ESXi-6.5.0.html
happy patching
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО01-09-2018 11:37 AM
тАО01-09-2018 11:37 AM
Re: Spectre and Meltdown
Got it working! Upgraded my VC Appliance, patched the hosts, and still was showing unprotected. Powered off, and on the VM, it's now all green.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО01-10-2018 12:51 AM
тАО01-10-2018 12:51 AM
Re: Spectre and Meltdown
same here after Patch and PowerOFF/On all are green.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО01-10-2018 04:33 AM
тАО01-10-2018 04:33 AM
Re: Spectre and Meltdown
Again, the main Question: What about Firmware Updates for Gen7 Servers and below?
Sorry, but the update process of a Gen9 doesn't matter. Now, everyone knows that nobody needs an entitlement, but needs a statement if an update will be released for older hardware and when does it happen.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО01-11-2018 01:55 AM - last edited on тАО01-12-2018 02:41 AM by Parvez_Admin
тАО01-11-2018 01:55 AM - last edited on тАО01-12-2018 02:41 AM by Parvez_Admin
Re: Spectre and Meltdown
Thanks...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО01-11-2018 09:59 AM
тАО01-11-2018 09:59 AM
Re: Spectre and Meltdown
When will the GEN7 patch be available? Im scrambling here...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО01-11-2018 12:37 PM
тАО01-11-2018 12:37 PM
Re: Spectre and Meltdown
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО01-13-2018 04:02 PM
тАО01-13-2018 04:02 PM
Re: Spectre and Meltdown
You obviously don't understand HP's licensing and profit model. G6 and G7 are so far out of support that you can get an almost fully populated DL360 G6 for less than $300 pretty much anywhere. Unless you're willing to pay more than that (3-4 times as much as that, actually) for support, they could care less that you have problems with the hardware. The answer is to upgrade your hardware and repeat the cycle in another three years.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО01-15-2018 04:02 AM
тАО01-15-2018 04:02 AM
Re: Spectre and Meltdown
next roud ....
https://newsroom.intel.com/news/intel-security-issue-update-addressing-reboot-issues/
vmware already pulled back their updates...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО01-15-2018 04:55 AM
тАО01-15-2018 04:55 AM
Re: Spectre and Meltdown
https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-a00039267en_us
also HP pulled back their Bios 2.54 for Gen9...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО01-15-2018 08:07 AM
тАО01-15-2018 08:07 AM
Re: Spectre and Meltdown
OK so can I assume you are using sarcasm? Your statement is kind of ridiculous, servers and infrastructure replacement isn't quite the same as sheeple jonesing the latest iPhone. The amount of G6 and G7 kit still in service in IT/IS departments is enormous. Even when you replace critical performance components and servers most IT departments will frequently re-purpose for lower performance requirements and cold type storage. That's why you can still buy HP Carepacks for G7 gear and I suspect you could probably find carepacks for G6 kit too.
Please put me down for notification of G6 and G7 mitigation of the Spectre vulnerability for BIOS ROM updates please.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО01-15-2018 04:26 PM
тАО01-15-2018 04:26 PM
Re: Spectre and Meltdown
Did everyone see that the Gen9 ROMs have been pulled?
https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-a00039267en_us
https://newsroom.intel.com/news/intel-security-issue-update-addressing-reboot-issues/
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО01-16-2018 01:35 AM
тАО01-16-2018 01:35 AM
Re: Spectre and Meltdown
Perfect !
So now we have Dell pulling back their updates, HPE pulling back their G9 updates ( G8 still under investigation), and no news from HPE on Gen 7 (coordinating with HPE TAM on our end ). Cisco on their hand have played safe, no updates till 18th Feb 2018 !
We have hundreds of Gen 7 servers in production !!
And ideally speaking, Gen 7 was retired on 30th April 2013 - so the support with regard to critical patches should be entertained till 30th April 2018 ... no ?!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО01-16-2018 02:21 AM
тАО01-16-2018 02:21 AM
Re: Spectre and Meltdown
Got a link to the Dell pulls?