// For flags

CVE-2020-7207

 

Severity Score

6.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A local elevation of privilege using physical access security vulnerability was found in HPE Proliant Gen10 Servers using Intel Innovation Engine (IE). This attack requires a physical attack to the server motherboard. To mitigate this issue, ensure your server is always physically secured. HPE will not address this issue in the impacted Gen 10 servers listed. HPE recommends using appropriate physical security methods as a compensating control to disallow an attacker from having physical access to the server main circuit board.

Se encontró una vulnerabilidad de elevación local de privilegios usando la seguridad de acceso físico en HPE Proliant Gen10 Servers que utiliza Intel Innovation Engine (IE). Este ataque requiere un ataque físico a la tarjeta madre del servidor. Para mitigar este problema, asegúrese de que su servidor esté siempre protegido físicamente. HPE no abordará este problema en los servidores Gen 10 listados que están afectados . HPE recomienda el uso de métodos de seguridad física apropiados como el control de compensación para no permitir que un atacante tenga acceso físico a la tarjeta del circuito principal del servidor

*Credits: N/A
CVSS Scores
Attack Vector
Physical
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-01-16 CVE Reserved
  • 2020-11-05 CVE Published
  • 2023-07-22 EPSS Updated
  • 2024-08-04 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Hp
Search vendor "Hp"
Apollo 2000 Firmware
Search vendor "Hp" for product "Apollo 2000 Firmware"
--
Affected
in Hp
Search vendor "Hp"
Apollo 2000
Search vendor "Hp" for product "Apollo 2000"
--
Safe
Hp
Search vendor "Hp"
Apollo 4200 Gen10 Firmware
Search vendor "Hp" for product "Apollo 4200 Gen10 Firmware"
--
Affected
in Hp
Search vendor "Hp"
Apollo 4200 Gen10
Search vendor "Hp" for product "Apollo 4200 Gen10"
--
Safe
Hp
Search vendor "Hp"
Apollo 4500 Firmware
Search vendor "Hp" for product "Apollo 4500 Firmware"
--
Affected
in Hp
Search vendor "Hp"
Apollo 4500
Search vendor "Hp" for product "Apollo 4500"
--
Safe
Hp
Search vendor "Hp"
Proliant Xl230k Gen10 Firmware
Search vendor "Hp" for product "Proliant Xl230k Gen10 Firmware"
--
Affected
in Hp
Search vendor "Hp"
Proliant Xl230k Gen10
Search vendor "Hp" for product "Proliant Xl230k Gen10"
--
Safe
Hp
Search vendor "Hp"
Proliant Xl270d Gen10 Firmware
Search vendor "Hp" for product "Proliant Xl270d Gen10 Firmware"
--
Affected
in Hp
Search vendor "Hp"
Proliant Xl270d Gen10
Search vendor "Hp" for product "Proliant Xl270d Gen10"
--
Safe
Hp
Search vendor "Hp"
Proliant Bl460c Gen10 Firmware
Search vendor "Hp" for product "Proliant Bl460c Gen10 Firmware"
--
Affected
in Hp
Search vendor "Hp"
Proliant Bl460c Gen10
Search vendor "Hp" for product "Proliant Bl460c Gen10"
--
Safe
Hp
Search vendor "Hp"
Proliant Dl120 Gen10 Firmware
Search vendor "Hp" for product "Proliant Dl120 Gen10 Firmware"
--
Affected
in Hp
Search vendor "Hp"
Proliant Dl120 Gen10
Search vendor "Hp" for product "Proliant Dl120 Gen10"
--
Safe
Hp
Search vendor "Hp"
Proliant Dl160 Gen10 Firmware
Search vendor "Hp" for product "Proliant Dl160 Gen10 Firmware"
--
Affected
in Hp
Search vendor "Hp"
Proliant Dl160 Gen10
Search vendor "Hp" for product "Proliant Dl160 Gen10"
--
Safe
Hp
Search vendor "Hp"
Proliant Dl180 Gen10 Firmware
Search vendor "Hp" for product "Proliant Dl180 Gen10 Firmware"
--
Affected
in Hp
Search vendor "Hp"
Proliant Dl180 Gen10
Search vendor "Hp" for product "Proliant Dl180 Gen10"
--
Safe
Hp
Search vendor "Hp"
Proliant Dl360 Gen10 Firmware
Search vendor "Hp" for product "Proliant Dl360 Gen10 Firmware"
--
Affected
in Hp
Search vendor "Hp"
Proliant Dl360 Gen10
Search vendor "Hp" for product "Proliant Dl360 Gen10"
--
Safe
Hp
Search vendor "Hp"
Proliant Dl380 Gen10 Firmware
Search vendor "Hp" for product "Proliant Dl380 Gen10 Firmware"
--
Affected
in Hp
Search vendor "Hp"
Proliant Dl380 Gen10
Search vendor "Hp" for product "Proliant Dl380 Gen10"
--
Safe
Hp
Search vendor "Hp"
Proliant Dl560 Gen10 Firmware
Search vendor "Hp" for product "Proliant Dl560 Gen10 Firmware"
--
Affected
in Hp
Search vendor "Hp"
Proliant Dl560 Gen10
Search vendor "Hp" for product "Proliant Dl560 Gen10"
--
Safe
Hp
Search vendor "Hp"
Proliant Dl580 Gen10 Firmware
Search vendor "Hp" for product "Proliant Dl580 Gen10 Firmware"
--
Affected
in Hp
Search vendor "Hp"
Proliant Dl580 Gen10
Search vendor "Hp" for product "Proliant Dl580 Gen10"
--
Safe
Hp
Search vendor "Hp"
Proliant Ml110 Gen10 Firmware
Search vendor "Hp" for product "Proliant Ml110 Gen10 Firmware"
--
Affected
in Hp
Search vendor "Hp"
Proliant Ml110 Gen10
Search vendor "Hp" for product "Proliant Ml110 Gen10"
--
Safe
Hp
Search vendor "Hp"
Proliant Ml350 Gen10 Firmware
Search vendor "Hp" for product "Proliant Ml350 Gen10 Firmware"
--
Affected
in Hp
Search vendor "Hp"
Proliant Ml350 Gen10
Search vendor "Hp" for product "Proliant Ml350 Gen10"
--
Safe
Hp
Search vendor "Hp"
Synergy 480 Gen10 Firmware
Search vendor "Hp" for product "Synergy 480 Gen10 Firmware"
--
Affected
in Hp
Search vendor "Hp"
Synergy 480 Gen10
Search vendor "Hp" for product "Synergy 480 Gen10"
--
Safe
Hp
Search vendor "Hp"
Synergy 660 Gen10 Firmware
Search vendor "Hp" for product "Synergy 660 Gen10 Firmware"
--
Affected
in Hp
Search vendor "Hp"
Synergy 660 Gen10
Search vendor "Hp" for product "Synergy 660 Gen10"
--
Safe
Hp
Search vendor "Hp"
Proliant E910 Firmware
Search vendor "Hp" for product "Proliant E910 Firmware"
--
Affected
in Hp
Search vendor "Hp"
Proliant E910
Search vendor "Hp" for product "Proliant E910"
--
Safe
Hp
Search vendor "Hp"
Proliant Xl170r Gen10 Firmware
Search vendor "Hp" for product "Proliant Xl170r Gen10 Firmware"
--
Affected
in Hp
Search vendor "Hp"
Proliant Xl170r Gen10
Search vendor "Hp" for product "Proliant Xl170r Gen10"
--
Safe
Hp
Search vendor "Hp"
Proliant Xl190r Gen10 Firmware
Search vendor "Hp" for product "Proliant Xl190r Gen10 Firmware"
--
Affected
in Hp
Search vendor "Hp"
Proliant Xl190r Gen10
Search vendor "Hp" for product "Proliant Xl190r Gen10"
--
Safe
Hp
Search vendor "Hp"
Proliant Xl230k Gen10 Firmware
Search vendor "Hp" for product "Proliant Xl230k Gen10 Firmware"
--
Affected
in Hp
Search vendor "Hp"
Proliant Xl230k Gen10
Search vendor "Hp" for product "Proliant Xl230k Gen10"
--
Safe
Hp
Search vendor "Hp"
Proliant Xl450 Gen10 Firmware
Search vendor "Hp" for product "Proliant Xl450 Gen10 Firmware"
--
Affected
in Hp
Search vendor "Hp"
Proliant Xl450 Gen10
Search vendor "Hp" for product "Proliant Xl450 Gen10"
--
Safe