CVE Feed

    Dashboard / CVE / CVE-2020-7207

    CVE-2020-7207

    A local elevation of privilege using physical access security vulnerability was found in HPE Proliant Gen10 Servers using Intel Innovation Engine (IE). This attack requires a physical attack to the server motherboard. To mitigate this issue, ensure your server is always physically secured. HPE will not address this issue in the impacted Gen 10 servers listed. HPE recommends using appropriate physical security methods as a compensating control to disallow an attacker from having physical access to the server main circuit board.

    Published:Nov 5, 2020
    Last Modified:Nov 21, 2024
    EPS:Nov 5, 2020
    EPSS Score:0.00057
    CVSS Score:6.8

    Affected Products

    Vendor
    Hp
    Product
    Apollo 2000
    Vendor
    Hp
    Product
    Apollo 2000 Firmware
    Vendor
    Hp
    Product
    Apollo 4200 Gen10
    Vendor
    Hp
    Product
    Apollo 4200 Gen10 Firmware
    Vendor
    Hp
    Product
    Apollo 4500
    Vendor
    Hp
    Product
    Apollo 4500 Firmware
    Vendor
    Hp
    Product
    Proliant Bl460c Gen10
    Vendor
    Hp
    Product
    Proliant Bl460c Gen10 Firmware
    Vendor
    Hp
    Product
    Proliant Dl120 Gen10
    Vendor
    Hp
    Product
    Proliant Dl120 Gen10 Firmware
    Vendor
    Hp
    Product
    Proliant Dl160 Gen10
    Vendor
    Hp
    Product
    Proliant Dl160 Gen10 Firmware
    Vendor
    Hp
    Product
    Proliant Dl180 Gen10
    Vendor
    Hp
    Product
    Proliant Dl180 Gen10 Firmware
    Vendor
    Hp
    Product
    Proliant Dl360 Gen10
    Vendor
    Hp
    Product
    Proliant Dl360 Gen10 Firmware
    Vendor
    Hp
    Product
    Proliant Dl380 Gen10
    Vendor
    Hp
    Product
    Proliant Dl380 Gen10 Firmware
    Vendor
    Hp
    Product
    Proliant Dl560 Gen10
    Vendor
    Hp
    Product
    Proliant Dl560 Gen10 Firmware
    Vendor
    Hp
    Product
    Proliant Dl580 Gen10
    Vendor
    Hp
    Product
    Proliant Dl580 Gen10 Firmware
    Vendor
    Hp
    Product
    Proliant E910
    Vendor
    Hp
    Product
    Proliant E910 Firmware
    Vendor
    Hp
    Product
    Proliant Ml110 Gen10
    Vendor
    Hp
    Product
    Proliant Ml110 Gen10 Firmware
    Vendor
    Hp
    Product
    Proliant Ml350 Gen10
    Vendor
    Hp
    Product
    Proliant Ml350 Gen10 Firmware
    Vendor
    Hp
    Product
    Proliant Xl170r Gen10
    Vendor
    Hp
    Product
    Proliant Xl170r Gen10 Firmware
    Vendor
    Hp
    Product
    Proliant Xl190r Gen10
    Vendor
    Hp
    Product
    Proliant Xl190r Gen10 Firmware
    Vendor
    Hp
    Product
    Proliant Xl230k Gen10
    Vendor
    Hp
    Product
    Proliant Xl230k Gen10 Firmware
    Vendor
    Hp
    Product
    Proliant Xl270d Gen10
    Vendor
    Hp
    Product
    Proliant Xl270d Gen10 Firmware
    Vendor
    Hp
    Product
    Proliant Xl450 Gen10
    Vendor
    Hp
    Product
    Proliant Xl450 Gen10 Firmware
    Vendor
    Hp
    Product
    Synergy 480 Gen10
    Vendor
    Hp
    Product
    Synergy 480 Gen10 Firmware
    Vendor
    Hp
    Product
    Synergy 660 Gen10
    Vendor
    Hp
    Product
    Synergy 660 Gen10 Firmware

    Exploits

    No exploit reference

    Common Weakness Enumeration

    No CWE recorded yet

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High