News: 1663057814

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

One month after Black Hat exposure HP enterprise kit still unpatched

(2022/09/13)


Multiple high-severity firmware bugs in HP enterprise computers remain unpatched, some more than a year after Binarly security researchers disclosed the vulnerabilities to HP and then discussed them at the Black Hat security conference last month.

This means that the vulnerabilities, with severity scores ranging from 7.5 to 8.2, can still be exploited by miscreants looking to perform a range of nefarious deeds, from stealing data to shutting down the machine altogether. And because the bugs were the subject of a [1]Black Hat talk , would-be cybercriminals essentially have a how-to kit available at their disposal.

HP is "aware of potential SMM vulnerabilities reported by Binarly," according to a spokesperson, who directed The Register to a security alert from March that addressed one of the bugs ( [2]CVE-2022-23930 ).

[3]

"Security is always a top priority for HP and we appreciate Binarly's contributions to help make HP products more secure," the spokesperson said in an emailed statement. "We encourage all customers to keep their systems updated with the latest software, drivers, and firmware to help protect against vulnerabilities."

[4]

[5]

However, patches for three of the bugs (CVE-2022-31644,CVE-2022-31645 and CVE-2022-31646) across multiple business notebooks, desktops, retail point-of-sale systems, and workstations were still listed as "pending" according to an [6]August security bulletin , while CVE-2022-31640 and CVE-2022-31641 remained unpatched in some workstation models and thin-client PCs as of September 9.

HP did not respond to The Register 's questions about when it would issue fixes for these devices.

[7]Teradici re-emerges as 'HP Anyware' to replace ZCentral Remote Boost

[8]Critical hole in Atlassian Bitbucket allows any miscreant to hijack servers

[9]80,000 internet-connected cameras still vulnerable after critical patch offered

[10]Google urges open source community to fuzz test code

Binarly CEO and co-founder Alex Matrosov said his team disclosed the vulnerabilities to HP in July 2021 and April 2022 before discussing the bugs in a Black Hat talk last month and then posting a blog about them last week.

"The main reason for the blog on September 8 was raising additional awareness since we see a lot of issues have been triggered in our clients enterprise environments on completely patched HP devices," he told The Register .

[11]

In the [12]blog , the Binarly security researchers detail six arbitrary code execution vulnerabilities due to System Management Mode (SMM) memory corruption problems. Specifically, these include:

[13]CVE-2022-23930 , a stack-based buffer overflow vulnerability that leads to escalating privileges to SMM. CVSS score: 8.2.

[14]CVE-2022-31644 , out-of-bounds write, due to improper input validation in a Communication Buffer. This could allow an attacker to bypass Secure Boot and other security mechanisms and install a firmware backdoor in BIOS for persistence. CVSS score: 7.5.

[15]

[16]CVE-2022-31645 , another out-of-bounds write vulnerability that could also lead to a backdoor in BIOS. CVSS score: 8.2.

[17]CVE-2022-31646 , an out-of-bounds write vulnerability based on direct memory manipulation API functionality that leads to privilege escalation. CVSS score: 8.2.

[18]CVE-2022-31640 , a callout vulnerability that could allow an attacker to access the SMM and execute arbitrary code. CVSS score: 7.5.

[19]CVE-2022-31641 , another SMM callout vulnerability that could lead to arbitrary code execution. CVSS score: 7.5.

When asked if the Binarly researchers had any insight into when HP planned to fix the flaws, Matrosov said he hadn't heard from the vendor.

"It should be patched already according to the coordinated disclosure timeline on Aug. 10," he added.

Still, he noted that firmware holes can be especially difficult to fully fix because they typically impact not just one vendor, but everyone that uses the Independent BIOS Developers (IBV) code in their UEFI firmware software.

"Even device vendors sometimes have difficulty identifying all the affected products due to supply chain complexity," Matrosov said.

To help companies "recover from these repeatable failures," the company created and open sourced [20]Binarly FwHunt , he added. It also provides a [21]free service that scans UEFI firmware images for vulnerabilities. ®

Get our [22]Tech Resources



[1] https://binarly.io/posts/Black_Hat_2022_The_Intel_PPAM_attack_story/index.html

[2] https://support.hp.com/us-en/document/ish_5817864-5817896-16/hpsbhf03776

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YyBUuLGzo0k2w6H68s3kCwAAAIA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YyBUuLGzo0k2w6H68s3kCwAAAIA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YyBUuLGzo0k2w6H68s3kCwAAAIA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://support.hp.com/us-en/document/ish_6664419-6664458-16/hpsbhf03806

[7] https://www.theregister.com/2022/07/26/teradici_now_hp_anyware/

[8] https://www.theregister.com/2022/08/29/atlassian_bitbucket_critical_bug/

[9] https://www.theregister.com/2022/08/24/hikvision_camera_patch/

[10] https://www.theregister.com/2022/09/08/google_fuzz_rewards/

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YyBUuLGzo0k2w6H68s3kCwAAAIA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[12] https://binarly.io/posts/Binarly_Finds_Six_High_Severity_Firmware_Vulnerabilities_in_HP_Enterprise_Devices/index.html

[13] https://binarly.io/advisories/BRLY-2022-010/index.html

[14] https://binarly.io/advisories/BRLY-2022-011/index.html

[15] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YyBUuLGzo0k2w6H68s3kCwAAAIA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[16] https://binarly.io/advisories/BRLY-2022-012/index.html

[17] https://binarly.io/advisories/BRLY-2022-013/index.html

[18] https://binarly.io/advisories/BRLY-2021-046/index.html

[19] https://binarly.io/advisories/BRLY-2021-047/index.html

[20] https://github.com/binarly-io/FwHunt

[21] https://www.fwhunt.run/

[22] https://whitepapers.theregister.com/



Once upon a time...

Joe W

.... HP had engineers. I fondly remember lengthy discussions with one of them about some things we tried to do with a programmable function generator, which worked out.... ok-ish (not the engineer's fault, but rather a limitation of the function generator - and we did not have the funds to buy another one). Then this part of HP got spun out as "Agilent" (who continued doing great stuff - not sure about right now, I am no longer in that field).

Same with printers. The old Laserjets were monsters - and reliable. The newer ones? We had a colour Laserjet where the toner cassettes were installed one atop the other on the side of the printer. Every 6 to 8 months we had to take that toner stack apart and thoroughly clean it - dust from the upper cassettes ended up un the lower ones, seriously messing up the colours. Not fun. And messy (though one of my mates / colleagues had all sorts of tricks and could do that really quite fast).

And likely the same with laptops etc.

And UEFI is a bloody mess anyways. Always has been. Complexity is the enemy of a robust and easy to fix system - but complexity caused by the requirements (yeah, I get the idea behind UEFI etc. - doesn't mean I must like it).

Cosmotronic Software Unlimited Inc. does not warrant that the
functions contained in the program will meet your requirements or that
the operation of the program will be uninterrupted or error-free.
However, Cosmotronic Software Unlimited Inc. warrants the
diskette(s) on which the program is furnished to be of black color and
square shape under normal use for a period of ninety (90) days from the
date of purchase.
NOTE: IN NO EVENT WILL COSMOTRONIC SOFTWARE UNLIMITED OR ITS
DISTRIBUTORS AND THEIR DEALERS BE LIABLE TO YOU FOR ANY DAMAGES, INCLUDING
ANY LOST PROFIT, LOST SAVINGS, LOST PATIENCE OR OTHER INCIDENTAL OR
CONSEQUENTIAL DAMAGES.
-- Horstmann Software Design, the "ChiWriter" user manual