Hewlett Packard Enterprise Product Security Vulnerability Alerts

Intel Management Engine (ME) and Server Platform Services (SPS) Firmware Security Vulnerability (CVE-2017-5706/CVE-2017-5709)

Version 2.0 :  Last Updated: November 29th, 2017

This website is updated frequently, as new product information becomes available.

Recently, one of our suppliers, Intel, discovered a potential security vulnerability in their Server Platform Services (SPS) firmware. The security vulnerability affected several of their processor architectures; however, not all of the impacted Intel server processor architectures are used in HPE products. Specifically, the SPS/ME firmware used in Intel’s architecture can be compromised using physical access. As a result, non-authenticated code may be executed in the SPS environment outside of the visibility of the user and operating system administrator.

These vulnerabilities are not unique to HPE servers and will affect any systems using Intel’s identified processor architectures with impacted firmware revisions.

Usage Instructions and Definitions for CVE Vulnerability Information

Data

Definition

Product Family

High-level product description.

Product Name

Detailed product description.

CVE-XXXX

Indicates whether the specific product is affected by the cited vulnerability.

(Impacted Y/N)

Impacted

Indicates whether the specific product is directly affected by the cited vulnerability or is indirectly affected due to a dependence on a separate, embedded or associated product.

Direct/Indirect

If Impacted

Information regarding how to address a vulnerability.

Mitigation Info

Notes

Miscellaneous information regarding the vulnerability.

Link to Security Bulletin

Link to HPE's Security Bulletin

 

Use the following table to find vulnerability information.

Product Category

Product

Sub- Category

Product Name

 Impacted (Yes/No)

If Impacted - Mitigation

Link(s) to security bulletin (Vendor)

Hybrid IT

Apollo

HPE Apollo 2000 System

Yes

https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-a00036596en_us

https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00086&languageid=en-fr&ref=hvper.com

Hybrid IT

Apollo

HPE Apollo 4510 System

Yes

https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-a00036596en_us

https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00086&languageid=en-fr&ref=hvper.com

Hybrid IT

Apollo

HPE Apollo 6000 DLC System

Yes

https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-a00036596en_us

https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00086&languageid=en-fr&ref=hvper.com

Hybrid IT

Servers

HPE ProLiant BL460c Gen10 Server Blade

Yes

https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-a00036596en_us

https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00086&languageid=en-fr&ref=hvper.com

Hybrid IT

Servers

HPE ProLiant DL20 Gen9 Server

Yes

https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-a00036596en_us

https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00086&languageid=en-fr&ref=hvper.com

Hybrid IT

Servers

HPE ProLiant DL360 Gen10 Server

Yes

https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-a00036596en_us

https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00086&languageid=en-fr&ref=hvper.com

Hybrid IT

Servers

HPE ProLiant DL380 Gen10 Server

Yes

https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-a00036596en_us

https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00086&languageid=en-fr&ref=hvper.com

Hybrid IT

Servers

HPE ProLiant DL560 Gen10 Server

Yes

https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-a00036596en_us

https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00086&languageid=en-fr&ref=hvper.com

Hybrid IT

Servers

HPE ProLiant DL580 Gen10 Server

Yes

https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-a00036596en_us

https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00086&languageid=en-fr&ref=hvper.com

Hybrid IT

Servers

HPE ProLiant m710x Server Cartridge

Yes

https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-a00036596en_us

https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00086&languageid=en-fr&ref=hvper.com

Hybrid IT

Servers

HPE ProLiant ML110 Gen10 Server

Yes

https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-a00036596en_us

https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00086&languageid=en-fr&ref=hvper.com

Hybrid IT

Servers

HPE ProLiant ML30 Gen9 Server

Yes

https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-a00036596en_us

https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00086&languageid=en-fr&ref=hvper.com

Hybrid IT

Servers

HPE ProLiant ML350 Gen10 Server

Yes

https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-a00036596en_us

https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00086&languageid=en-fr&ref=hvper.com

Hybrid IT

Apollo

HPE ProLiant XL170r Gen10 Server

Yes

https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-a00036596en_us

https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00086&languageid=en-fr&ref=hvper.com

Hybrid IT

Apollo

HPE ProLiant XL190r Gen10 Server )

Yes

https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-a00036596en_us

https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00086&languageid=en-fr&ref=hvper.com

Hybrid IT

Apollo

HPE ProLiant XL230k Gen10 Server )

Yes

https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-a00036596en_us

https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00086&languageid=en-fr&ref=hvper.com

Hybrid IT

Apollo

HPE ProLiant XL450 Gen10 Server

Yes

https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-a00036596en_us

https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00086&languageid=en-fr&ref=hvper.com

Hybrid IT

Servers

HPE Synergy 480 Gen10 Compute Module

Yes

https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-a00036596en_us

https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00086&languageid=en-fr&ref=hvper.com

Hybrid IT

Servers

HPE Synergy 660 Gen10 Compute Module

Yes

https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-a00036596en_us

https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00086&languageid=en-fr&ref=hvper.com

Hybrid IT

Servers

HPE ConvergedSystem 500 for SAP HANA

Yes

https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-a00036596en_us

https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00086&languageid=en-fr&ref=hvper.com