SB2025010717 - Multiple vulnerabilities in Certain HPE SimpliVity Servers
Published: January 7, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Input validation error (CVE-ID: CVE-2022-33894)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to insufficient input validation in the BIOS firmware. A local user can execute arbitrary code with escalated privileges.
2) Exposure of resource to wrong sphere (CVE-ID: CVE-2022-38087)
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to exposure of resource to wrong sphere in BIOS firmware. A local user can gain access to sensitive information.
Remediation
Install update from vendor's website.