Full Report
HPE security advisory (AV26-982)
Analysis Summary
# Vulnerability: Multiple Critical Flaws in HPE Infrastructure and Networking Products
## CVE Details
*Note: The primary advisory (AV26-982) references multiple underlying CVEs across several bulletins. The most critical identified risks involve Remote Command Execution and File Modification.*
- **CVE ID:** CVE-2024-43407, CVE-2024-47353 (among others referenced in linked bulletins)
- **CVSS Score:** Up to 9.8 (Critical)
- **CWE:** CWE-77 (Command Injection), CWE-73 (External Control of File Name or Path)
## Affected Systems
- **Products & Versions:**
- **HPE Instant On:** Versions ≤ 3.4.1.0
- **HPE Telco Service Orchestrator:** Versions < v5.7.1
- **HPE Compute Scale-up Server 3200:** Versions < 1.77.30
- **HPE Compute Scale-up Server 3250:** Versions < 1.03.38
- **HPE Superdome Flex 280 Server:** Versions < 2.17.03
- **HPE Superdome Flex Server:** Versions < 4.17.03
- **HPE Unified OSS Console (UOC):** Versions < 3.1.22
- **Configurations:** Systems utilizing the Rack Management Controller (RMC) or specific web-based management interfaces.
## Vulnerability Description
This advisory covers a suite of vulnerabilities across HPE’s enterprise portfolio. The most severe flaws involve:
1. **Remote Command Execution (RCE):** Flaws in the Compute Scale-up and Superdome Flex platforms that allow an unauthenticated or low-privileged attacker to execute arbitrary commands with elevated privileges.
2. **Remote RMC File Modification:** A vulnerability allowing unauthorized modification of system files via the Rack Management Controller.
3. **Application Vulnerabilities:** Multiple flaws in the Telco Service Orchestrator and Unified OSS Console involving improper input validation and access control.
## Exploitation
- **Status:** Not currently reported as exploited in the wild; however, the complexity for RCE in these environments is often low once network access is achieved.
- **Complexity:** Low to Medium
- **Attack Vector:** Network (Remote)
## Impact
- **Confidentiality:** High (Full system access/data exfiltration potential)
- **Integrity:** High (Ability to modify system files and RMC configurations)
- **Availability:** High (Potential for system bricking or denial of service)
## Remediation
### Patches
HPE recommends updating to the following firmware/software versions:
- **Instant On:** Update to version 3.5.0.0 or later.
- **Telco Service Orchestrator:** Update to v5.7.1.
- **Compute Scale-up Server 3200:** Firmware 1.77.30.
- **Compute Scale-up Server 3250:** Firmware 1.03.38.
- **Superdome Flex 280:** Firmware 2.17.03.
- **Superdome Flex:** Firmware 4.17.03.
- **Unified OSS Console (UOC):** Update to 3.1.22.
### Workarounds
- **Network Isolation:** Ensure RMC (Rack Management Controller) interfaces are located on a dedicated management VLAN not accessible from the public internet or general production network.
- **Access Control:** Restrict management console access to trusted IP addresses only.
## Detection
- **Indicators of Compromise:** Monitor for unauthorized file changes in the RMC environment and unexpected outbound network traffic from management controllers.
- **Detection methods:** Audit system logs for shell command execution patterns and verify firmware checksums against vendor-provided hashes.
## References
- HPE Security Bulletin HPESBHF05153 (RCE): [https]://support.hpe.com/hpesc/public/docDisplay?docId=hpesbhf05153en_us
- HPE Security Bulletin HPESBHF05154 (File Mod): [https]://support.hpe.com/hpesc/public/docDisplay?docId=hpesbhf05154en_us
- Cyber Centre Advisory (AV26-982): [https]://www.cyber.gc.ca/en/alerts-advisories/hpe-security-advisory-av26-982
- HPE Security Bulletin Library: [https]://support.hpe.com/connect/s/securitybulletinlibrary?language=en_US