Boston Labs Announcement: Intel Security Vulnerabilities Regarding Intel® Management Engine (ME)
Based on items identified through a comprehensive security review, an attacker could gain unauthorized access to platform, Intel® ME feature, and 3rd party secrets protected by the Intel® Management Engine (ME), Intel® Server Platform Service (SPS), or Intel® Trusted Execution Engine (TXE).
This includes scenarios where a successful attacker could:
For more information, please see the Intel Support article/notice INTEL-SA-00086 - it is imperative to act as soon as possible.
“The following is available from Supermicro, covering the products which are affected, and how to patch against this threat.
“Intel has issued a security notice (INTEL-SA-00086) for select systems that use Intel® Management Engine (ME), Intel® Server Platform Services (SPS), and Intel® Trusted Execution Engine (TXE) with the objective of enhancing firmware resilience. As a result, Intel has identified security vulnerabilities that could potentially place impacted platforms at risk.
The following X11 and embedded/desktop Supermicro Motherboards are impacted by this issue.
There are two options to determine if your system is impacted.
1) You can run the tool that Intel provides for detection (Intel-SA-00086 Detection Tool)
2) Refer to the table below to identify your system and associated Motherboard.
To update your systems, navigate to the web page for the associated motherboard and update to the BIOS specified below.
Please use SUM 2.0.0 (20171108) for Purley platforms and SUM 2.0.1 for Apollolake and Denverton platforms. Not using the above versions to update BIOS revisions may hang the system after downgrades.
Additional systems will be added to this list as information becomes available”
If you have any queries regarding this topic, please contact our support team via the partner portal, or email [email protected]
See the Supermicro website for more.
Dual Processor (2S) X11 Systems
- All X11 Systems need to be updated to version 2.0 or greater of BIOS
- Availability is pending with the following 10 mother boards scheduled to be updated by Friday 12/1
If you have any queries regarding this topic, please contact our support team via the partner portal, or email [email protected]
Single Processor (1P) X11 Systems
- The Update for X11SS_ Greenlow (E3-1200 v5/v6) motherboards is available now
- The Update for X11SP_ Purley (Intel Xeon Processor Scalable Family) is TBD
|
If you have any queries regarding this topic, please contact our support team via the partner portal, or email [email protected]
|
If you have any queries regarding this topic, please contact our support team via the partner portal, or email [email protected]
SuperBlade, MicroBlade and MicroCloud Systems
|
If you have any queries regarding this topic, please contact our support team via the partner portal, or email [email protected]
Multi-Processor X11 Motherboards
- All X11 Systems need to be updated to version 2.0 or greater of BIOS
- Availability is TBD
Embedded, Workstation and Desktop Systems
- All systems based on the following processors need to be updated
- 6th, 7th & 8th Generation Intel® Core™ Processor Family
- Intel® Xeon® Processor W Family
- Intel® Atom® C3000 Processor Family
- Apollo Lake Intel® Atom Processor E3900 series
- Apollo Lake Intel® Pentium™
- Availability is TBD
|
If you have any queries regarding this topic, please contact our support team via the partner portal, or email [email protected]
To help our clients make informed decisions about new technologies, we have opened up our research & development facilities and actively encourage customers to try the latest platforms using their own tools and if necessary together with their existing hardware. Remote access is also available
Boston Germany will be exhibiting at GPEC Digital in Leipzig!