SUPPORT COMMUNICATION- SECURITY BULLETIN HPSBHF03656 rev. 4 - Intel® Chipset Device Software INF Utility Security Update

Related Vulnerabilities: CVE-2019-14596  

HP has been notified of a potential security vulnerability in Intel® Chipset Device Software INF Utility that may allow denial of service via local access. Intel has released software updates to mitigate this potential vulnerability.

Potential Security Impact:
Denial of Service.
Source: HP, HP Product Security Response Team (PSRT)
Reported by: Intel®

VULNERABILITY SUMMARY

HP has been notified of a potential security vulnerability in Intel® Chipset Device Software INF Utility that may allow denial of service via local access. Intel has released software updates to mitigate this potential vulnerability.
Reference Number
INTEL-SA-00306 (in English), CVE-2019-14596 (in English), PSR-2020-0027
SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed.
See RESOLUTION section below.
BACKGROUND
For a PGP signed version of this security bulletin please write to: hp-security-alert@hp.com
CVSS 3.0 Base Metrics
Reference
Base Vector
Base Score
CVE-2019-14596
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H
5.9
RESOLUTION
Intel has released updates to mitigate the potential vulnerability. HP has identified the affected platforms and the corresponding SoftPaq with minimum versions that mitigate the potential vulnerability. See the affected platforms listed below.
Newer versions may become available and identified minimum versions may become obsolete. If a SoftPaq Link becomes invalid, check the HP Customer Support - Software and Driver Downloads site to obtain the latest update for your product model.
HP recommends keeping your system up to date with the latest firmware and software.
note:
This bulletin might be updated when new information and/or SoftPaqs are available. Sign up for HP Subscriptions to be notified and receive:
  • Product support eAlerts
  • Driver updates
  • Security bulletin updates
Not available: Softpaq not available due to technical or logistical constraints.
Check support page: The listed SoftPaq has been removed from download site. SoftPaqs with newer versions might be available on the HP Customer Support - Software and Driver Downloads site.

Business Desktop PCs

Product Name
Updated Version
SoftPaq #
SoftPaq Link
HP 260 G2
10.1.18243.8188
SP101125
HP 260 G3
10.1.18243.8188
SP101129
HP 280 G2 MT
10.1.18243.8188
SP104082
HP 280 G2 SFF
10.1.18243.8188
SP104082
HP 280 G3 MT
10.1.18243.8188
SP104082
HP 406 MT
10.1.18243.8188
SP104082
HP Desktop Pro G2
10.1.18121.8164
SP100997
HP Desktop Pro G3
10.1.18121.8164
SP101185
HP Elite Slice
10.1.18243.8188
SP101125
HP Elite Slice G2 - with Zoom Rooms
10.1.18243.8188
SP101129
HP Elite Slice G2 - Audio Ready with Zoom Rooms
10.1.18243.8188
SP101129
HP Elite Slice G2 - Intel Unit
10.1.18243.8188
SP101129
HP Elite Slice G2 - Partner Ready with Microsoft Teams Rooms
10.1.18243.8188
SP101129
HP Elite Slice G2 - with Microsoft Teams Rooms
10.1.18243.8188
SP101129
HP ProDesk 600 G2 DM
10.1.18243.8188
SP101125
HP EliteDesk 800 G2 DM
10.1.18243.8188
SP101125
HP EliteDesk 800 G3 DM
10.1.18243.8188
SP101129
HP EliteDesk 800 G3 SFF
10.1.18243.8188
SP101129
HP EliteDesk 800 G3 TWR
10.1.18243.8188
SP101129
HP EliteDesk 800 G4 DM
10.1.18121.8164
SP101012
HP EliteDesk 800 G4 SFF
10.1.18121.8164
SP101012
HP EliteDesk 800 G4 TWR
10.1.18121.8164
SP101012
HP EliteDesk 800 G5 DM
10.1.18121.8164
SP101012
HP EliteDesk 800 G5 SFF
10.1.18121.8164
SP101012
HP EliteDesk 800 G5 TWR
10.1.18121.8164
SP101012
HP EliteDesk 880 G3 TWR
10.1.18243.8188
SP101129
HP EliteDesk 880 G4 TWR
10.1.18121.8164
SP101012
HP EliteDesk 880 G5 TWR
10.1.18121.8164
SP101012
HP EliteOne 1000 G1 All-in-One
10.1.18243.8188
SP101129
HP EliteOne 1000 G2 All-in-One
10.1.18121.8164
SP101012
HP EliteOne 800 G2 AiO GPU T/NT
10.1.18243.8188
SP101125
HP EliteOne 800 G2 AiO T/NT
10.1.18243.8188
SP101125
HP EliteOne 800 G3 All-in-One
10.1.18243.8188
SP101129
HP EliteOne 800 G3 GPU All-in-One
10.1.18243.8188
SP101129
HP EliteOne 800 G4 All-in-One
10.1.18121.8164
SP101012
HP EliteOne 800 G4 GPU All-in-One
10.1.18121.8164
SP101012
HP EliteOne 800 G5 All-in-One
10.1.18121.8164
SP101012
HP ProDesk 400 G2 DM
10.1.18243.8188
SP101125
HP ProDesk 400 G3 DM
10.1.18243.8188
SP101129
HP ProDesk 400 G4 DM
10.1.18121.8164
SP101012
HP ProDesk 400 G4 MT
10.1.18243.8188
SP101129
HP ProDesk 400 G4 SFF
10.1.18243.8188
SP101129
HP ProDesk 400 G5 DM
10.1.18121.8164
SP101012
HP ProDesk 400 G5 MT
10.1.18121.8164
SP101012
HP ProDesk 400 G5 SFF
10.1.18121.8164
SP101012
HP ProDesk 400 G6 MT
10.1.18121.8164
SP101012
HP ProDesk 400 G6 SFF
10.1.18121.8164
SP101012
HP ProDesk 480 G4 MT
10.1.18243.8188
SP101129
HP ProDesk 480 G5 MT
10.1.18121.8164
SP101012
HP ProDesk 480 G6 MT
10.1.18121.8164
SP101012
HP ProDesk 600 G3 DM
10.1.18243.8188
SP101129
HP ProDesk 600 G3 MT
10.1.18243.8188
SP101129
HP ProDesk 600 G3 SFF
10.1.18243.8188
SP101129
HP ProDesk 600 G4 DM
10.1.18121.8164
SP101012
HP ProDesk 600 G4 MT
10.1.18121.8164
SP101012
HP ProDesk 600 G4 SFF
10.1.18121.8164
SP101012
HP ProDesk 600 G5 DM
10.1.18121.8164
SP101012
HP ProDesk 600 G5 MT
10.1.18121.8164
SP101012
HP ProDesk 600 G5 SFF
10.1.18121.8164
SP101012
HP ProDesk 680 G3 MT
10.1.18243.8188
SP101129
HP ProDesk 680 G4 MT
10.1.18121.8164
SP101012
HP ProDesk 680 G4 PCI MT
10.1.18121.8164
SP101012
HP ProOne 400 G2 AiO T/NT
10.1.18243.8188
SP101125
HP ProOne 400 G3 AiO
10.1.18243.8188
SP101129
HP ProOne 400 G4 AiO
10.1.18121.8164
SP101012
HP ProOne 400 G5 AiO
10.1.18121.8164
SP101012
HP ProOne 440 G4 AiO
10.1.18121.8164
SP101012
HP ProOne 440 G5 AiO
10.1.18121.8164
SP101012
HP ProOne 600 G2 AiO T/NT
10.1.18243.8188
SP101125
HP ProOne 600 G3 AiO
10.1.18243.8188
SP101129
HP ProOne 600 G4 AiO
10.1.18121.8164
SP101012
HP ProOne 600 G5 AiO
10.1.18121.8164
SP101012

Business Notebook PCs

Product Name
Updated Version
SoftPaq #
SoftPaq Link
HP 340 G3
10.1.18243.8188
SP101720
HP 340 G4
10.1.18243.8188
SP101834
HP 346 G3
10.1.18243.8188
SP101720
HP 346 G4
10.1.18243.8188
SP101718
HP 348 G3
10.1.18243.8188
SP101720
HP 348 G4
10.1.18243.8188
SP101834
HP Elite Dragonfly
10.1.18121.8164
SP101377
HP Elite x2 1012 G1
10.1.18243.8188
SP101370
HP Elite x2 1012 G1 Tablet
10.1.18243.8188
SP101370
HP Elite x2 1012 G1 Tablet with Travel Keyboard
10.1.18243.8188
SP101370
HP Elite x2 1012 G2
10.1.18243.8188
SP101171
HP Elite x2 1013 G3
10.1.18243.8188
SP101171
HP Elite x2 G4
10.1.18121.8164
SP101377
HP EliteBook 1030 G1
10.1.18243.8188
SP101370
HP EliteBook 1040 G4
10.1.18243.8188
SP101171
HP EliteBook 1050 G1
10.1.18121.8164
SP101012
HP EliteBook 820 G3
10.1.18243.8188
SP101370
HP EliteBook 820 G4
10.1.18243.8188
SP101171
HP EliteBook 828 G3
10.1.18243.8188
SP101370
HP EliteBook 828 G4
10.1.18243.8188
SP101171
HP EliteBook 830 G5
10.1.18243.8188
SP101171
HP EliteBook 830 G6
10.1.18121.8164
SP101377
HP EliteBook 836 G5
10.1.18243.8188
SP101171
HP EliteBook 836 G6
10.1.18121.8164
SP101377
HP EliteBook 840 G3
10.1.18243.8188
SP101370
HP EliteBook 840 G4
10.1.18243.8188
SP101171
HP EliteBook 840 G5
10.1.18243.8188
SP101171
HP EliteBook 840 G5 Healthcare Edition
10.1.18243.8188
SP101171
HP EliteBook 840 G6
10.1.18121.8164
SP101377
HP EliteBook 840 G6 Healthcare Edition
10.1.18121.8164
SP101377
HP EliteBook 840r G4
10.1.18243.8188
SP101171
HP EliteBook 846 G5
10.1.18243.8188
SP101171
HP EliteBook 846 G5 Healthcare Edition
10.1.18243.8188
SP101171
HP EliteBook 846 G6
10.1.18121.8164
SP101377
HP EliteBook 846 G6 Healthcare Edition
10.1.18121.8164
SP101377
HP EliteBook 846r G4
10.1.18243.8188
SP101171
HP EliteBook 848 G3
10.1.18243.8188
SP101370
HP EliteBook 848 G4
10.1.18243.8188
SP101171
HP EliteBook 850 G3
10.1.18243.8188
SP101370
HP EliteBook 850 G4
10.1.18243.8188
SP101171
HP EliteBook 850 G5
10.1.18243.8188
SP101171
HP EliteBook 850 G6
10.1.18121.8164
SP101377
HP EliteBook Folio 1040 G3
10.1.18243.8188
SP101370
HP EliteBook Folio G1
10.1.18243.8188
SP101370
HP EliteBook x360 1020 G2
10.1.18243.8188
SP101171
HP EliteBook x360 1030 G2
10.1.18243.8188
SP101171
HP EliteBook x360 1030 G3
10.1.18243.8188
SP101171
HP EliteBook x360 1030 G4
10.1.18121.8164
SP101377
HP EliteBook x360 1040 G5
10.1.18243.8188
SP101171
HP EliteBook x360 1040 G6
10.1.18121.8164
SP101377
HP EliteBook x360 830 G5
10.1.18243.8188
SP101171
HP EliteBook x360 830 G6
10.1.18121.8164
SP101377
HP Pro x2 612 G2
10.1.18243.8188
SP101171
HP ProBook 11 G2 EE
10.1.18243.8188
SP101595
HP ProBook 430 G4
10.1.18243.8188
SP101171
HP ProBook 430 G5
10.1.18243.8188
SP101171
HP ProBook 430 G6
10.1.18121.8164
SP101377
HP ProBook 430 G7
10.1.18121.8164
SP101005
HP ProBook 440 G4
10.1.18243.8188
SP101171
HP ProBook 440 G5
10.1.18243.8188
SP101171
HP ProBook 440 G6
10.1.18121.8164
SP101377
HP ProBook 440 G7
10.1.18121.8164
SP101005
HP ProBook 450 G4
10.1.18243.8188
SP101171
HP ProBook 450 G5
10.1.18243.8188
SP101171
HP ProBook 450 G6
10.1.18121.8164
SP101377
HP ProBook 450 G7
10.1.18121.8164
SP101005
HP ProBook 470 G4
10.1.18243.8188
SP101171
HP ProBook 470 G5
10.1.18243.8188
SP101171
HP ProBook 640 G3
10.1.18243.8188
SP101171
HP ProBook 640 G4
10.1.18243.8188
SP101171
HP ProBook 640 G5
10.1.18121.8164
SP101377
HP ProBook 650 G3
10.1.18243.8188
SP101171
HP ProBook 650 G4
10.1.18121.8164
SP101012
HP ProBook 650 G5
10.1.18121.8164
SP101377
HP ProBook x360 11 G1 EE
10.1.17861.8101
SP101607
HP ProBook x360 11 G2 EE
10.1.18121.8164
SP101657
HP ProBook x360 11 G3 EE
10.1.18243.8188
SP101564
HP ProBook x360 11 G4 EE
10.1.18121.8164
sp101056
HP ProBook x360 11 G5 EE
10.1.18243.8188
SP101564
HP ProBook x360 11 G6 EE
10.1.18121.8164
SP101056
HP ProBook x360 440 G1
10.1.18243.8188
SP101171
HP ZBook 14u G4
10.1.18243.8188
SP101171
HP ZBook 14u G5
10.1.18243.8188
SP101171
HP ZBook 14u G6
10.1.18121.8164
SP101377
HP ZBook 15 G3
10.1.18243.8188
SP101370
HP ZBook 15 G4
10.1.18243.8188
SP101171
HP ZBook 15 G5
10.1.18121.8164
SP101012
HP Zbook 15 G6
10.1.18121.8164
SP101012
HP ZBook 15u G3
10.1.18243.8188
SP101370
HP ZBook 15u G4
10.1.18243.8188
SP101171
HP ZBook 15u G5
10.1.18243.8188
SP101171
HP ZBook 15u G6
10.1.18121.8164
SP101377
HP ZBook 17 G3
10.1.18243.8188
SP101370
HP ZBook 17 G4
10.1.18243.8188
SP101171
HP ZBook 17 G5
10.1.18121.8164
SP101012
HP Zbook 17 G6
10.1.18121.8164
SP101012
HP ZBook Studio G3
10.1.18243.8188
SP101370
HP ZBook Studio G4
10.1.18243.8188
SP101171
HP ZBook Studio G5
10.1.18121.8164
SP101012
HP ZBook Studio x360 G5
10.1.18121.8164
SP101012
HP ZBook x2 G4
10.1.18243.8188
SP101171
HP ZHAN 66 Pro 13 G2
10.1.18121.8164
SP101377
HP ZHAN 66 Pro 14 G2
10.1.18121.8164
SP101377
HP ZHAN 66 Pro 14 G3
10.1.18121.8164
SP101005
HP ZHAN 66 Pro 15 G2
10.1.18121.8164
SP101377
HP ZHAN 66 Pro 15 G3
10.1.18121.8164
SP101005
HP ZHAN 66 Pro G1
10.1.18243.8188
SP101171
HP ZHAN X 13 G2
10.1.18121.8164
SP101377

Desktop Workstation PCs

Product Name
Updated Version
SoftPaq #
SoftPaq Link
HP Z1 G2 Workstation
10.0.18362.267
SP101759
HP Z1 G3 Workstation
10.0.18362.267
SP101759
HP Z2 G4 Mini Workstation
10.1.18228.8176
SP107367
HP Z2 G4 SFF Workstation
10.1.18228.8176
SP107367
HP Z2 G4 TWR Workstation
10.1.18228.8176
SP107367
HP Z2 Mini G3 Workstation
10.1.18228.8176
SP107367
HP Z228 MT Workstation
10.1.18228.8176
Not Available
Not Available
HP Z230 SFF Workstation
10.1.18228.8176
Not Available
Not Available
HP Z230 TWR Workstation
10.1.18228.8176
Not Available
Not Available
HP Z238 Microtower Workstation
10.1.18228.8176
SP107367
HP Z240 SFF Workstation
10.1.18228.8176
SP107367
HP Z240 Tower Workstation
10.1.18228.8176
SP107367
HP Z4 G4 Core-X Workstation
10.1.18263.8193
SP101966
HP Z4 G4 Workstation (Xeon W)
10.1.18263.8193
SP101966
HP Z420 Workstation
10.0.18362.267
SP101759
HP Z440 Workstation
10.0.18362.267
SP101759
HP Z6 G4 Workstation
10.1.18263.8193
SP101966
HP Z620 Workstation
10.0.18362.267
SP101759
HP Z640 Workstation
10.0.18362.267
SP101759
HP Z8 G4 Workstation
10.1.18263.8193
SP101966
HP Z820 Workstation
10.0.18362.267
SP101759
HP Z840 Workstation
10.0.18362.267
SP101759
HP ZVR Backpack Workstation G1
10.1.18243.8188
SP101601

Retail Point-of-Sale systems

Product Name
Updated Version
SoftPaq #
SoftPaq Link
HP Engage Flex Pro Retail System
10.1.18121.8164
SP101012
HP Engage Flex Pro-C Retail System
10.1.18121.8164
SP101012
HP Engage Go Mobile System
10.1.18243.8188
SP101171
HP Engage One Retail System
10.1.18243.8188
SP101129
HP MP9 G2 Retail System
10.1.18243.8188
SP101125
HP MP9 G4 Retail System
10.1.18121.8164
SP101012
HP RP2 Retail System, Model 2000
10.1.18243.8188
SP101125
HP RP2 Retail System, Model 2020
10.1.18243.8188
SP101125
HP RP2 Retail System, Model 2030 
10.1.18243.8188
SP101125
HP RP9 G1 Retail System
10.1.18243.8188
SP101125

Immersive PCs

Product Name
Updated Version
SoftPaq
SoftPaq Link
Sprout Pro by HP
10.1.18228.8176
SP100500
Sprout Pro by HP G2
10.1.18228.8176
SP100500

Thin Clients

Product Name
Updated Version
SoftPaq
SoftPaq Link
HP t430 Thin Client
10.1.13.3
SP102196
HP t628 Thin Client
10.1.1.45
SP102339

Home Desktop PCs

Product Name
Updated Version
SoftPaq #
SoftPaq Link
HP Slim pD0xxx Desktop
10.1.18295.8201
SP103938
HP Slim S01 Desktop
10.1.18295.8201
SP103938
HP 280 G4
10.1.18295.8201
SP103938
HP 290 G2
10.1.18295.8201
SP103938
HP Slim pF0xxx Desktop
10.1.18295.8201
SP103938
HP Slim S01 Desktop
10.1.18295.8201
SP103938
HP ENVY TE01-0xxx Desktop
10.1.18295.8201
SP103938
HP Pavilion Gaming TG01-0xxx Desktop
10.1.18295.8201
SP103938
HP Pavilion TP01-0xxx Desktop PC
10.1.18295.8201
SP103938
HP 190-0xxx Desktop PC
10.1.18295.8201
SP103936
HP All-in-One 20-c4xx
10.1.18295.8201
SP104308
HP All-in-One 22-c4xx
10.1.18295.8201
SP104308
HP Pavilion 24 All-in-One PC
10.1.18295.8201
SP104308
HP Pavilion 27 All-in-One PC
10.1.18295.8201
SP104308
HP Envy All-in-One PC 27-b2XX
10.1.18295.8201
SP103979
HP Envy Curved All-in-One PC 34-b1xx
10.1.18295.8201
SP103979
HP 22 All-in-One
10.1.18295.8201
SP104308
HP 200 G3 AIO
10.1.18295.8201
SP104308
HP Pavilion Wave 600-a3XX Desktop
10.1.18295.8201
SP103937
OMEN X by HP 900-2xx Desktop PC
10.1.18088.8158
SP103949
HP ENVY All-in-One 32-a0xxx
10.1.18295.8201
SP104166
HP M01-D0xxx Desktop PC
10.1.18295.8201
SP103938
HP N01-D0xxx Desktop PC
10.1.18295.8201
SP103938
HP 280 G5
10.1.18295.8201
SP103938
HP 282 G5
10.1.18295.8201
SP103938
HP 288 G5
10.1.18295.8201
SP103938
HP 290 G3
10.1.18295.8201
SP103938
HP M01-F0xxx Desktop PC
10.1.18295.8201
SP103938
HP N01-F0xxx Desktop PC
10.1.18295.8201
SP103938

Home Notebook PCs

Product Name
Updated Version
SoftPaq #
SoftPaq Link
OMEN by HP Laptop PC 15 15-dh0xxx
10.1.18295.8201
SP105452
OMEN by HP Laptop PC 15 15-dh4xxx
10.1.18295.8201
SP105452
OMEN by HP Laptop PC 15 17-cb0xxx
10.1.18295.8201
SP105452
OMEN by HP Laptop PC 15 17-cb1xxx
10.1.18295.8201
SP105452
HP ENVY x360 15 Convertible PC 15-ed0xxx
10.1.18295.8201
SP105870
Third Party Security Patches: Third party security patches that are to be installed on systems running HP software products should be applied in accordance with the customer's patch management policy.
Support: For issues about implementing the recommendations of this Security Bulletin, visit https://www.hp.com/go/contacthp to learn about your HP support options.
Report: To report a potential security vulnerability with any HP supported product, send email to: hp-security-alert@hp.com.
Subscribe: To initiate a subscription to receive future HP Security Bulletin alerts via email, visit https://www.hp.com/go/alerts.
Security Bulletin Archive: To view released Security Bulletins, search the HP Support Site for "security bulletin".
Software Product Category: The Software Product Category is represented in the title by the two characters following HPSB.
PI
HP Printing and Imaging
HF
HP Hardware and Firmware
GN
HP General Software
It is strongly recommended that security related information being communicated to HP be encrypted using PGP, especially exploit information.
To get the security-alert PGP key, please send an e-mail message as follows:
Subject: get key
System management and security procedures must be reviewed frequently to maintain system integrity. HP is continually reviewing and enhancing the security features of software products to provide customers with current secure solutions.

"HP is broadly distributing this Security Bulletin in order to bring to the attention of users of the affected HP products the important security information contained in this Bulletin.HP recommends that all users determine the applicability of this information to their individual situations and take appropriate action.HP does not warrant that this information is necessarily accurate or complete for all user situations and, consequently, HP will not be responsible for any damages resulting from user's use or disregard of the information provided in this Bulletin.To the extent permitted by law, HP disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose, title and non-infringement."
REVISION HISTORY : Version:1 – 24 February 2020 Initial release. Version: 2 – 24 April 2020 Updated platform lists for DT Workstations, Retail Point of Sale Systems, and Business PCs. Version: 3 – 25 June 2020, updated Business PC and Home PC platform lists. Version: 4 – 6 October 2020 Update information in Resolution section, and updated SoftPaq information in Workstation, Thin Client and Home Notebook tables.