This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

HP Broadcom NIC firmware update

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

HP Broadcom Integrated NIC firmware update…
- http://secunia.com/advisories/39003/
Release Date: 2010-03-16
Last Update: 2010-03-26
Criticality level: Highly critical
Impact: System access
Software:
Broadcom Integrated NIC Management Firmware for HP PCs 1.x
Broadcom Integrated NIC Management Firmware for HP PCs 8.x
Solution: Update to version 1.40.0.0 or 8.08 (available via softpaq SP47557).
CVE Reference(s): CVE-2010-0104
Original Advisory: HPSBGN02511 SSRT100022:
http://h20000.www2.hp.com/bizsupport/TechS…ectID=c02048471
Potential Security Impact: Remote execution of arbitrary code…
… Products containing the Broadcom Integrated NIC firmware listed at the HP URL above…

- http://web.nvd.nist.gov/view/vuln/detail?v…d=CVE-2010-0104
Last revised: 03/19/2010 - "Unspecified vulnerability in the Broadcom Integrated NIC Management Firmware 1.x before 1.40.0.0 and 8.x before 8.08 on the HP Small Form Factor and Microtower platforms allows remote attackers to execute arbitrary code via unknown vectors…"
CVSS v2 Base Score: 10.0 (HIGH)

:ph34r:
FYI…

Broadcom NetXtreme integrated NIC firmware - update available
- http://secunia.com/advisories/39107/
Release Date: 2010-03-26
Criticality level: Highly critical
Impact: System access
Where: From remote
Solution Status: Vendor Patch
Operating System: Broadcom NetXtreme Series
Original Advisory: US-CERT VU#512705:
http://www.kb.cert.org/vuls/id/512705

> http://www.kb.cert.org/vuls/id/CRDY-83VKGZ
Date Updated: 2010-03-25 - "…Vendor Statement
Affected devices are only vulnerable when Secure ASF (RMCP/RSP) manageability is enabled on the platform , which may not be the typical default system configuration.
Affected devices and the latest vulnerable management firmware version are:
BCM5751, BCM5752, BCM5753, BCM5754, BCM5755, BCM5756, BCM5764, BCM5787: v8.04, BCM57760: v8.07, BCM5761: v1.24.0.9
Updated versions of management firmware for all affected devices is now available to PC OEMs as part of the Broadcom NetXtreme 14.0 software release.
Available work-arounds include: disabling the management firmware and/or Secure ASF (RSP) support and blocking UDP port 664 traffic from unauthorized sources in enterprise firewalls.
Vendor Information: The vendor has not provided us with any further information regarding this vulnerability…"

- http://www.broadcom.com/support/ethernet_n…mine_driver.php

> http://h20000.www2.hp.com/bizsupport/TechS…ectID=c02048471
"… HP Small Form Factor or Microtower PC with Broadcom Integrated NIC Firmware, Remote Execution of Arbitrary Code…
Broadcom Integrated NIC Firmware…
RESOLUTION: HP has made softpaq SP47557 available to resolve the vulnerability.
This softpaq is available at ftp://ftp.hp.com/pub/softpaq/sp47501-48000/sp47557.exe "

- http://web.nvd.nist.gov/view/vuln/detail?v…d=CVE-2010-0104
Last revised: 03/19/2010 - "Unspecified vulnerability in the Broadcom Integrated NIC Management Firmware 1.x before 1.40.0.0 and 8.x before 8.08 on the HP Small Form Factor and Microtower platforms allows remote attackers to execute arbitrary code via unknown vectors…"
CVSS v2 Base Score: 10.0 (HIGH)

:ph34r: