ZeroHour

CVE-2020-7207

CVSS 3.1
6.8 medium
EPSS
<1%p43
Published
()
Modified
Description

A local elevation of privilege using physical access security vulnerability was found in HPE Proliant Gen10 Servers using Intel Innovation Engine (IE). This attack requires a physical attack to the server motherboard. To mitigate this issue, ensure your server is always physically secured. HPE will not address this issue in the impacted Gen 10 servers listed. HPE recommends using appropriate physical security methods as a compensating control to disallow an attacker from having physical access to the server main circuit board.

Vendors
hp
Products
apollo 2000 firmware, apollo 4200 gen10 firmware, apollo 4500 firmware, proliant xl230k gen10 firmware, proliant xl270d gen10 firmware, proliant bl460c gen10 firmware, proliant dl120 gen10 firmware, proliant dl160 gen10 firmware, proliant dl180 gen10 firmware, proliant dl360 gen10 firmware, proliant dl380 gen10 firmware, proliant dl560 gen10 firmware
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.