Intel memory firmware bug hits hundreds of products

By

Dell and HP first to ship fixes.

Intel has pushed out fixes for Optane SSD bugs that first emerged a year ago.

Intel memory firmware bug hits hundreds of products

While rated as “high” rather than “critical”, with Common Vulnerability Scoring System ratings over 7, the bugs will have knock-on impacts on any servers using the affected Optane SSD and Optane SSD Data Center firmware.

There are three Common Vulnerabilities and Exposures (CVE) numbers rated high.

CVE-2021-33078 is a race condition in a firmware thread, giving a privileged user a vector for denial-of-service.

In CVE-2021-33077, a flow control management bug could be exploited by an unauthenticated local user to escalate their privilege.

And in CVE-2021-33080, an unauthenticated local user could gain sensitive information or escalation of privilege, because of uncleared debug information in the firmware.

Affected and supported products include all versions of Optane SSD DC D4800X; SSD DC P4800X and P4801X before version E2010600; SSD P5800X Series before version L3010200; all versions of SSD 905P/900P; and all versions of Optane Memory H10 and H20 with solid state storage.

So far, Dell (with more than 500 products impacted) and HP (around 700 products impacted) have started shipping new firmware to fix the bugs.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

Woolworths' CSO is Optus-bound

Woolworths' CSO is Optus-bound

Australia's super funds told to assess authentication controls

Australia's super funds told to assess authentication controls

Hackers abuse modified Salesforce app to steal data, extort companies

Hackers abuse modified Salesforce app to steal data, extort companies

The Northern Beaches Women's Shelter hones focus on tech-enabled abuse

The Northern Beaches Women's Shelter hones focus on tech-enabled abuse

Log In

  |  Forgot your password?