SB20241022390 - HPE Superdome Flex 280 servers update for Intel 3rd Gen Xeon firmware



SB20241022390 - HPE Superdome Flex 280 servers update for Intel 3rd Gen Xeon firmware

Published: October 22, 2024

Security Bulletin ID SB20241022390
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Resource management error (CVE-ID: CVE-2024-25939)

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper management of internal resources within the application. Mirrored regions with different values in 3rd Generation Intel Xeon Scalable Processors may allow a local privileged user to crash the system.


Remediation

Install update from vendor's website.