Dell OptiPlex 3080 HDP

Updating the system firmware improves performance.

Atom Feed

Version 2.26.0
2024-08-13 01:42:32

This release contains security updates as disclosed in the Dell Security Advisory.

Urgency low
Reported Success 100% (low confidence)
Licenses
Security
Release Gating
Download Archive Firmware Details Compare with previous

Version 2.25.1
2024-06-12 02:58:05

Fixed the issue where the system updates the BIOS after you resume it from Sleep mode. This issue occurs when you try to update the BIOS in silent mode by using the Command prompt then enter the sleep mode.

Urgency low
Reported Success 100% (low confidence)
Licenses
Security
Release Gating
Download Archive Firmware Details Compare with previous

Version 2.24.0
2024-04-09 09:52:05

This stable release fixes the following issues:

  • This release contains security updates as disclosed in the Dell Security Advisories DSA2024-030 and DSA2024-066.

Urgency low
Reported Success 100% (low confidence)
Licenses
Security
Release Gating
Download Archive Firmware Details Compare with previous

Version 2.23.1
2024-02-06 07:36:40

This stable release fixes the following issues:

  • This release contains security updates as disclosed in the Dell Security Advisory DSA2023-344, DSA2023-364, DSA2023-435, DSA2023-449, and DSA2023-467.

Urgency low
Reported Success 100% (low confidence)
Licenses
Security
Release Gating
Download Archive Firmware Details Compare with previous

Version 2.22.0
2023-12-12 07:41:13

This stable release fixes the following issues:

  • Vulnerabilities in EDK2 Reference implementation of the UEFI Specification - CPG BIOS
  • Arbitrary file creation using Symlink leads to Privilege Escalation and Permanent DOS - CPG BIOS

Urgency low
Reported Success 100% (low confidence)
Fixed issues:
Licenses
Security
Release Gating
Download Archive Firmware Details Compare with previous

Version 2.21.1
2023-11-14 00:56:18

This stable release fixes the following issues:

  • This release contains security updates as disclosed in the Dell Security Advisory.For more information, see Dell Security Advisories and Notices.

Urgency low
Fixed issues:
Licenses
Security
Release Gating
Download Archive Firmware Details Compare with previous

Version 2.21.0 — not be suitable for production systems
2023-10-04 07:16:45

This stable release fixes the following issues:

  • Fixed the issue where the system can boot on the bootable key when the BIOS admin password is set.
  • Physical attack on UEFI Variables.

Urgency low
Licenses
Security
Release Gating
Download Archive Firmware Details Compare with previous

Version 2.20.0
2023-09-12 01:03:04

This stable release fixes the following issues:

  • EC: [Sustain][2023 July MIP] EC Main Trunk
  • EC: Dell CPG BIOS: EC Mailbox vulnerability
  • EFI: CPG BIOS: OpenSSL Vulnerabilities
  • EFI: OpenSSL Vulnerabilities - DPF BIOSConnect
  • EFI: 2023.3 IPU - BIOS Advisory
  • MCU: 2023.3 IPU - Processor Advisory
  • ME: 2023.3 IPU (Aug 2023) - ME/TXE
  • Others: Data write Vulnerabilitity In dell precision workstation 7910(RuntimeAcpiSmm )
  • Others: Privilege Escalation in UEFI firmware of Latitude 3190's TcgSmm

Urgency low
Licenses
Security
Release Gating
Download Archive Firmware Details Compare with previous

Version 2.19.1
2023-06-12 04:12:48

This stable release fixes the following issues:

  • Fixed the issue where incomplete information is displayed in the Dell Firmware Update Utility when you try to update the BIOS.

Urgency low
Licenses
Security
Release Gating
Download Archive Firmware Details Compare with previous

Version 2.19.0
2023-05-30 06:54:05

This stable release fixes the following issues:

  • EC update to v1.26.0.
  • SetVariable NVRAM Corruption - CPG BIOS.

Urgency low
Fixed issues:
Licenses
Security
Release Gating
Download Archive Firmware Details Compare with previous

Version 2.18.0
2023-04-13 01:23:45

This stable release fixes the following issues:

  • DCSV-1145: BRLY-2022-054 - Stack buffer overflow vulnerability leads to arbitrary code execution in DXE drive.
  • DCSV-1178: BRLY-2022-087 - Memory leak vulnerability in DXE driver on Dell platform - CPG BIOS.
  • DCSV-1412_2023.2 IPU - INTEL - BIOS Advisory.
  • DCSV-1439: CPG BIOS: TianoCore#3387 SmmEntryPoint underflow allowing potential SMM privilege escalation.
  • DCSV-1457: BIOS - Intel PROSet/Wireless WiFi and Killer WiFi Advisory.

Urgency low
Fixed issues:
Licenses
Security
Release Gating
Download Archive Firmware Details Compare with previous

Version 2.17.1
2023-02-14 01:35:19

This stable release fixes the following issues:

  • Improved the stability of the system.

Urgency low
Licenses
Security
Release Gating
Download Archive Firmware Details Compare with previous

Version 2.16.0
2022-10-13 00:46:25

This stable release fixes the following issues:

  • Embargo Intel Aug 2022 - BIOS - DPF BIOSConnect.
  • TOCTOU Race Conditions in UEFI Vulnerability OS and Firmware DMA(PSRC-18431).
  • Intel Chipset Firmware.(2022.3 IPU (Oct 2022) - ME)

Urgency low
Fixed issues:
Licenses
Security
Release Gating
Download Archive Firmware Details Compare with previous

Version 2.15.0
2022-09-14 02:29:42

This stable release fixes the following issues:

  • Added the Self-Healing Image Recovery (SHIR) and Connect Provisioning to improve the operating system recovery using BIOSConnect.

Urgency low
Licenses
Security
Release Gating
Download Archive Firmware Details Compare with previous

Version 2.14.0
2022-08-12 03:15:18

This stable release fixes the following issues:

  • DCSV-684: OpenSSL.
  • DCSV-741: Dell XPS BIOS vulnerability3 - XPS 15 9550 (PSRC-18144).
  • DCSV-792: Dell BIOS vulnerability2 - XPS 8940 (PSRC-18257).

Urgency low
Fixed issues:
  • CVE-2022-32493
  • CVE-2022-32484
  • CVE-2022-0778

    The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed form or explicit elliptic curve parameters with a base point encoded in compressed form. It is possible to trigger the infinite loop by crafting a certificate that has invalid explicit curve parameters. Since certificate parsing happens prior to verification of the certificate signature, any process that parses an externally supplied certificate may thus be subject to a denial of service attack. The infinite loop can also be reached when parsing crafted private keys as they can contain explicit elliptic curve parameters. Thus vulnerable situations include: - TLS clients consuming server certificates - TLS servers consuming client certificates - Hosting providers taking certificates or private keys from customers - Certificate authorities parsing certification requests from subscribers - Anything else which parses ASN.1 elliptic curve parameters Also any other applications that use the BN_mod_sqrt() where the attacker can control the parameter values are vulnerable to this DoS issue. In the OpenSSL 1.0.2 version the public key is not parsed during initial parsing of the certificate which makes it slightly harder to trigger the infinite loop. However any operation which requires the public key from the certificate will trigger the infinite loop. In particular the attacker can use a self-signed certificate to trigger the loop during verification of the certificate signature. This issue affects OpenSSL versions 1.0.2, 1.1.1 and 3.0. It was addressed in the releases of 1.1.1n and 3.0.2 on the 15th March 2022. Fixed in OpenSSL 3.0.2 (Affected 3.0.0,3.0.1). Fixed in OpenSSL 1.1.1n (Affected 1.1.1-1.1.1m). Fixed in OpenSSL 1.0.2zd (Affected 1.0.2-1.0.2zc).

Licenses
Security
Release Gating
Download Archive Firmware Details Compare with previous

Version 2.13.0
2022-07-25 02:02:58

This stable release fixes the following issues:

  • 2022.1 IPU (July 2022) - ME.
  • CPSE-11412: [Opti][CY20][Gazelle] 24 pcs of Gazelle 27" have no video

Urgency low
Fixed issues:
  • CVE-2022-32488

    Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.

  • CVE-2022-0004

    Hardware debug modes and processor INIT setting that allow override of locks for some Intel(R) Processors in Intel(R) Boot Guard and Intel(R) TXT may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

Licenses
Security
Release Gating
Download Archive Firmware Details Compare with previous

Version 2.12.1
2022-06-15 01:30:02

This stable release fixes the following issues:

  • Enhanced the BIOS recovery function.

Urgency low
Licenses
Security
Release Gating
Download Archive Firmware Details Compare with previous

Version 2.11.0
2022-05-19 00:11:42

This stable release fixes the following issues:

  • Firmware updates to address security vulnerabilities.

Urgency low
Licenses
Security
Release Gating
Download Archive Firmware Details Compare with previous

Version 2.10.3
2022-05-16 00:59:23

This stable release fixes the following issues:

  • Firmware updates to address security vulnerabilities.

Urgency low
Fixed issues:
  • CVE-2022-21166

    Incomplete cleanup in specific special register write operations for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2022-21127

    Incomplete cleanup in specific special register read operations for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2022-21123

    Incomplete cleanup of multi-core shared buffers for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2022-0005

    Sensitive information accessible by physical probing of JTAG interface for some Intel(R) Processors with SGX may allow an unprivileged user to potentially enable information disclosure via physical access.

  • CVE-2021-3712

    ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the string data and a field holding the buffer length. This contrasts with normal C strings which are repesented as a buffer for the string data which is terminated with a NUL (0) byte. Although not a strict requirement, ASN.1 strings that are parsed using OpenSSL's own "d2i" functions (and other similar parsing functions) as well as any string whose value has been set with the ASN1_STRING_set() function will additionally NUL terminate the byte array in the ASN1_STRING structure. However, it is possible for applications to directly construct valid ASN1_STRING structures which do not NUL terminate the byte array by directly setting the "data" and "length" fields in the ASN1_STRING array. This can also happen by using the ASN1_STRING_set0() function. Numerous OpenSSL functions that print ASN.1 data have been found to assume that the ASN1_STRING byte array will be NUL terminated, even though this is not guaranteed for strings that have been directly constructed. Where an application requests an ASN.1 structure to be printed, and where that ASN.1 structure contains ASN1_STRINGs that have been directly constructed by the application without NUL terminating the "data" field, then a read buffer overrun can occur. The same thing can also occur during name constraints processing of certificates (for example if a certificate has been directly constructed by the application instead of loading it via the OpenSSL parsing functions, and the certificate contains non NUL terminated ASN1_STRING structures). It can also occur in the X509_get1_email(), X509_REQ_get1_email() and X509_get1_ocsp() functions. If a malicious actor can cause an application to directly construct an ASN1_STRING and then process it through one of the affected OpenSSL functions then this issue could be hit. This might result in a crash (causing a Denial of Service attack). It could also result in the disclosure of private memory contents (such as private keys, or sensitive plaintext). Fixed in OpenSSL 1.1.1l (Affected 1.1.1-1.1.1k). Fixed in OpenSSL 1.0.2za (Affected 1.0.2-1.0.2y).

  • CVE-2021-28211

    A heap overflow in LzmaUefiDecompressGetInfo function in EDK II.

  • CVE-2021-28210

    An unlimited recursion in DxeCore in EDK II.

  • CVE-2019-14584

    Null pointer dereference in Tianocore EDK2 may allow an authenticated user to potentially enable escalation of privilege via local access.

Licenses
Security
Release Gating
Download Archive Firmware Details Compare with previous

Version 2.9.0 — not be suitable for production systems
2022-03-23 02:48:24

This stable release fixes the following issues:

  • Added the support for BIOS recovery when BIOS update is interrupted due to power loss.
  • Added a dialog box for the user to save Pre-boot System Diagnostics logs in a storage media before exiting the Diagnostics.

Urgency None
Licenses
Security
Release Gating
Download Archive Firmware Details Compare with previous

Version 2.8.1
2022-02-10 02:12:32

This stable release fixes the following issues:

  • Firmware updates to address security vulnerabilities.

Urgency None
Fixed issues:
  • CVE-2021-33107

    Insufficiently protected credentials in USB provisioning for Intel(R) AMT SDK before version 16.0.3, Intel(R) SCS before version 12.2 and Intel(R) MEBx before versions 11.0.0.0012, 12.0.0.0011, 14.0.0.0004 and 15.0.0.0004 may allow an unauthenticated user to potentially enable information disclosure via physical access.

  • CVE-2021-0183

    Improper Validation of Specified Index, Position, or Offset in Input in software for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Killer(TM) Wi-Fi in Windows 10 and 11 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

  • CVE-2021-0176

    Improper input validation in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Killer(TM) Wi-Fi in Windows 10 and 11 may allow a privileged user to potentially enable denial of service via local access.

  • CVE-2021-0175

    Improper Validation of Specified Index, Position, or Offset in Input in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Killer(TM) Wi-Fi in Windows 10 and 11 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

  • CVE-2021-0174

    Improper Use of Validation Framework in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Killer(TM) Wi-Fi in Windows 10 and 11 may allow a unauthenticated user to potentially enable denial of service via adjacent access.

  • CVE-2021-0173

    Improper Validation of Consistency within input in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Killer(TM) Wi-Fi in Windows 10 and 11 may allow a unauthenticated user to potentially enable denial of service via adjacent access.

  • CVE-2021-0170

    Exposure of Sensitive Information to an Unauthorized Actor in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Killer(TM) Wi-Fi in Windows 10 and 11 may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2021-0168

    Improper input validation in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Killer(TM) Wi-Fi in Windows 10 and 11 may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2021-0166

    Exposure of Sensitive Information to an Unauthorized Actor in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Killer(TM) Wi-Fi in Windows 10 and 11 may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2021-0165

    Improper input validation in firmware for Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and Killer(TM) Wi-Fi in Windows 10 and 11 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

  • CVE-2021-0164

    Improper access control in firmware for Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and Killer(TM) Wi-Fi in Windows 10 and 11 may allow an unauthenticated user to potentially enable escalation of privilege via local access.

  • CVE-2021-0161

    Improper input validation in firmware for Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and Killer(TM) Wi-Fi in Windows 10 and 11 may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2021-0127

    Insufficient control flow management in some Intel(R) Processors may allow an authenticated user to potentially enable a denial of service via local access.

  • CVE-2021-0156

    Improper input validation in the firmware for some Intel(R) Processors may allow an authenticated user to potentially enable an escalation of privilege via local access.

  • CVE-2021-0125

    Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via physical access.

  • CVE-2021-0124

    Improper access control in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via physical access.

  • CVE-2021-0119

    Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via physical access.

  • CVE-2021-0118

    Out-of-bounds read in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access.

  • CVE-2021-0117

    Pointer issues in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access.

  • CVE-2021-0116

    Out-of-bounds write in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access.

  • CVE-2021-0115

    Buffer overflow in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2021-0114

    Unchecked return value in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access.

  • CVE-2021-0111

    NULL pointer dereference in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access.

  • CVE-2021-0103

    Insufficient control flow management in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access.

  • CVE-2021-0107

    Unchecked return value in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2021-0091

    Improper access control in the firmware for some Intel(R) Processors may allow an unauthenticated user to potentially enable an escalation of privilege via local access.

  • INTEL-SA-00575
  • INTEL-SA-00539
  • INTEL-SA-00532
  • INTEL-SA-00527
Licenses
Security
Release Gating
Download Archive Firmware Details Compare with previous

Version 2.3.1
2021-11-19 01:36:55

This stable release fixes the following issues:

  • Firmware updates to address security vulnerabilities.
  • Firmware updates to address the Intel Security Advisory INTEL SA 00562.
  • Correct Wireless AC 3165 behavior when Fast Startup enable.

Urgency None
Licenses
Security
Release Gating
Download Archive Firmware Details Compare with previous

Version 2.2.1
2021-09-10 00:39:20

This stable release fixes the following issues:

  • Firmware updates to address security vulnerabilities.
  • Fixed the issue where the customized logo and product name are removed when you upgrade the BIOS and change the BIOS to its default settings.
  • Fixed the issue where the Administrator and System Password cannot be set through Windows Management Instrumentation (WMI) command.This issue occurs when you enter more than 16 characters.

Enhancements:

  • Reduced the fan noise.

Urgency high
Licenses
Security
Release Gating
Download Archive Firmware Details Compare with previous

Version 2.1.1 — not be suitable for production systems
2021-07-30 00:52:16

This stable release fixes the following issues:

  • Firmware updates to address security vulnerabilities.
  • DCSV2020-0044 - 2021.1 IPU UEFI update.
  • DCSV2020-0043 - 2021.1 IPU MCU update.
  • DCSV2020-0045 - 2021.1 IPU ME update.
  • DCSV2020-0044 - 2021.1 IPU BIOS ACM update.
  • Update DCSV2021-0013: CPG BIOS - Latitude - out of bounds read/write.
  • Update DCSV2021-0018: DCI Enablement.
  • Update DCSV2021-0003 - DBUtils_2_3.sys Get Impacted Platforms to v2.7 or higher.

Urgency critical
Fixed issues:
  • CVE-2021-21572

    Dell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local access to the system may potentially exploit this vulnerability to run arbitrary code and bypass UEFI restrictions.

  • CVE-2021-21571

    Dell UEFI BIOS https stack leveraged by the Dell BIOSConnect feature and Dell HTTPS Boot feature contains an improper certificate validation vulnerability. A remote unauthenticated attacker may exploit this vulnerability using a person-in-the-middle attack which may lead to a denial of service and payload tampering.

  • CVE-2020-12359

    Insufficient control flow management in the firmware for some Intel(R) Processors may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

  • CVE-2020-8700

    Improper input validation in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2020-24511

    Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2020-24516

    Modification of assumed-immutable data in subsystem in Intel(R) CSME versions before 13.0.47, 13.30.17, 14.1.53, 14.5.32, 15.0.22 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

  • CVE-2020-24506

    Out of bound read in a subsystem in the Intel(R) CSME versions before 12.0.81, 13.0.47, 13.30.17, 14.1.53 and 14.5.32 may allow a privileged user to potentially enable information disclosure via local access.

  • CVE-2020-8703

    Improper buffer restrictions in a subsystem in the Intel(R) CSME versions before 11.8.86, 11.12.86, 11.22.86, 12.0.81, 13.0.47, 13.30.17, 14.1.53, 14.5.32 and 15.0.22 may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2020-24507

    Improper initialization in a subsystem in the Intel(R) CSME versions before 11.8.86, 11.12.86, 11.22.86, 12.0.81, 13.0.47, 13.30.17, 14.1.53, 14.5.32, 13.50.11 and 15.0.22 may allow a privileged user to potentially enable information disclosure via local access.

Licenses
Security
Release Gating
Download Archive Firmware Details Compare with previous

Version 1.3.12
2021-07-30 03:11:29

This stable release fixes the following issues:

  • Improved the system boot performance.
  • Added support for Intel Wi-Fi 802.11ax for Ukraine region.

Urgency low
Licenses
Security
Release Gating
Download Archive Firmware Details Compare with previous

Version 1.3.1
2021-01-18 07:09:47

Dell security update.

Urgency medium
Fixed issues:
  • CVE-2020-12355

    Intel's CVE.

  • CVE-2020-12303

    Use after free in DAL subsystem for Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE 3.1.80, 4.0.30 may allow an authenticated user to potentially enable escalation of privileges via local access.

  • CVE-2020-12297

    Improper access control in Installer for Intel(R) CSME Driver for Windows versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel TXE 3.1.80, 4.0.30 may allow an authenticated user to potentially enable escalation of privileges via local access.

  • CVE-2020-8705

    Insecure default initialization of resource in Intel(R) Boot Guard in Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE versions before 3.1.80 and 4.0.30, Intel(R) SPS versions before E5_04.01.04.400, E3_04.01.04.200, SoC-X_04.00.04.200 and SoC-A_04.00.04.300 may allow an unauthenticated user to potentially enable escalation of privileges via physical access.

  • CVE-2020-8744

    Improper initialization in subsystem for Intel(R) CSME versions before12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE versions before 4.0.30 Intel(R) SPS versions before E3_05.01.04.200 may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2020-8745

    Insufficient control flow management in subsystem for Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25 , Intel(R) TXE versions before 3.1.80 and 4.0.30 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

  • VU#231329

    Replay Protected Memory Block (RPMB) protocol does not adequately defend against replay attacks

  • INTEL-TA-00391
  • CVE-2020-8695

    Observable discrepancy in the RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.

  • CVE-2020-8694

    Insufficient access control in the Linux kernel driver for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

  • INTEL-SA-00389
Licenses
Security
Release Gating
Download Archive Firmware Details Compare with previous

Version 1.2.0
2020-08-25 07:17:29

-Enhanced the configuration for NVMe Firmware Update feature.

  • Updated the Intel CPU microcode.
  • Updated the Embedded Controller Engine firmware.

Urgency medium
Licenses
Security
Release Gating
Download Archive Firmware Details Compare with previous

Version 1.1.0
2020-07-03 04:39:01

-Firmware updates to address security advisory.

Urgency critical
Fixed issues:
  • CVE-2020-0542

    Improper buffer restrictions in subsystem for Intel(R) CSME versions before 12.0.64, 13.0.32, 14.0.33 and 14.5.12 may allow an authenticated user to potentially enable escalation of privilege, information disclosure or denial of service via local access.

  • CVE-2020-0534

    Improper input validation in the DAL subsystem for Intel(R) CSME versions before 12.0.64, 13.0.32, 14.0.33 and 14.5.12 may allow an unauthenticated user to potentially enable denial of service via network access.

  • CVE-2020-0541

    Out-of-bounds write in subsystem for Intel(R) CSME versions before 12.0.64, 13.0.32, 14.0.33 and 14.5.12 may allow a privileged user to potentially enable escalation of privilege via local access.

  • INTEL-SA-00295
Licenses
Security
Release Gating
Download Archive Firmware Details Compare with previous

Version 1.0.7
2020-05-27 15:21:30

Fixes: Fixed the issue where the system powers on automatically when the AC adapter is connected to the system.

Enhancements:

  • Enhanced the stability of the system during shutdown.

Urgency medium
Licenses
Security
Release Gating
Download Archive Firmware Details Compare with previous

Version 1.0.5
2020-05-27 15:21:06

Initial release.

Urgency medium
Licenses
Security
Release Gating
Download Archive Firmware Details

LVFS © 2015 Richard Hughes with icons from Font Awesome and GeoIP data from IP2Location.

Linux Vendor Firmware Service Project a Series of LF Projects, LLC :: Charter