Vulnerability Description
A local elevation of privilege using physical access security vulnerability was found in HPE Proliant Gen10 Servers using Intel Innovation Engine (IE). This attack requires a physical attack to the server motherboard. To mitigate this issue, ensure your server is always physically secured. HPE will not address this issue in the impacted Gen 10 servers listed. HPE recommends using appropriate physical security methods as a compensating control to disallow an attacker from having physical access to the server main circuit board.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hp | Apollo 2000 Firmware | - |
| Hp | Apollo 2000 | - |
| Hp | Apollo 4200 Gen10 Firmware | - |
| Hp | Apollo 4200 Gen10 | - |
| Hp | Apollo 4500 Firmware | - |
| Hp | Apollo 4500 | - |
| Hp | Proliant Xl230K Gen10 Firmware | - |
| Hp | Proliant Xl230K Gen10 | - |
| Hp | Proliant Xl270D Gen10 Firmware | - |
| Hp | Proliant Xl270D Gen10 | - |
| Hp | Proliant Bl460C Gen10 Firmware | - |
| Hp | Proliant Bl460C Gen10 | - |
| Hp | Proliant Dl120 Gen10 Firmware | - |
| Hp | Proliant Dl120 Gen10 | - |
| Hp | Proliant Dl160 Gen10 Firmware | - |
| Hp | Proliant Dl160 Gen10 | - |
| Hp | Proliant Dl180 Gen10 Firmware | - |
| Hp | Proliant Dl180 Gen10 | - |
| Hp | Proliant Dl360 Gen10 Firmware | - |
| Hp | Proliant Dl360 Gen10 | - |
References
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpeVendor Advisory
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpeVendor Advisory
FAQ
What is CVE-2020-7207?
CVE-2020-7207 is a vulnerability with a CVSS score of 6.8 (MEDIUM). A local elevation of privilege using physical access security vulnerability was found in HPE Proliant Gen10 Servers using Intel Innovation Engine (IE). This attack requires a physical attack to the se...
How severe is CVE-2020-7207?
CVE-2020-7207 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-7207?
Check the references section above for vendor advisories and patch information. Affected products include: Hp Apollo 2000 Firmware, Hp Apollo 2000, Hp Apollo 4200 Gen10 Firmware, Hp Apollo 4200 Gen10, Hp Apollo 4500 Firmware.