Security Bulletins

Inspur takes security vulnerabilities very seriously and seeks to respond quickly and appropriately. We are working to resolve issues quickly when problems arise, and providing recommendations through security advisories and security notices.

Security Notice (SN): Provide information of general interest about security topics related to Inspur products or the use of Inspur products.

Security Advisory (SA): Provide information about security vulnerabilities identified with Inspur products, including any fixes, workarounds or other actions.

To report an Inspur product vulnerability or find out how vulnerabilities are handled, please visit the Product Security Incident Response page.


LATEST

Security Advisory – Intel Processors And SPS Vulnerabilities

On November 10th, Intel reported potential security vulnerabilities in some Intel Processors that may allow an authenticated user to potentially enable information disclosure or es…


Security Advisory – Multiple Buffer Overflow And Path Traversal Vulnerabilities In Some Inspur BMC

Multiple vulnerabilities in the Baseboard Management Controller(BMC) of INSPUR server could allow an remote attacker with administrator privileges to perform a denial of service at…


Security Advisory – Unsignature Verification Vulnerability In Some Inspur BMC

The Baseboard Management Controller (BMC) program of INSPUR server is weak in checking the firmware and lacks the signature verification mechanism, the attacker who obtains the adm…


Security Notice – Statement On Some Intel Processors And SPS Vulnerabilities

On November 10th, Intel reported potential security vulnerabilities in some Intel Processors that may allow an authenticated user to potentially enable information disclosure or es…


Security Advisory – Intel SRBDS Vulnerabilities

Intel reported potential security vulnerabilities in some Intel Processors that may allow an authenticated user to potentially enable information disclosure. intel-sa-00320:CVE-202…


Security Advisory – Intel SPS local DOS

Integer overflow in subsystem for Intel(R) CSME versions before 11.8.77, 11.12.77, 11.22.77 and Intel® TXE versions before 3.1.75, 4.0.25 and Intel(R) Server Platform Services (SPS…


Security Notice – Statement On Grub2 Vulnerability Aka BootHole

On July 29th, a researcher disclosed a vulnerability in Linux GRUB2 bootloaders called “BootHole” (CVE-2020-10713). An attacker may use the GRUB 2 flaw to hijack and tamper the GRU…


Security Notice – Statement On intel-sa-00295

Potential security vulnerabilities in Intel Converged Security and Manageability Engine (CSME), Intel Server Platform Services (SPS), Intel Trusted Execution Engine (TXE), Intel Ac…


Security Notice – Statement on the Side Channel Vulnerabilities “MDS” of Chips

On May 14, 2019, Intel disclosed four new side channel vulnerabilities (CVE-2018-12126, CVE-2018-12127, CVE-2018-12130, and CVE-2019-11091), Intel unified this series of vulnerabilities into Microarchitectural Data Sampling vulnerabilities…


1 2