-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2017.1349
 HPESBHF03750 rev.1 - HPE Network Products including Comware 5, Comware 7
           and VCX running NTP, Remote Denial of Service (DoS),
         Unauthorized Modification, Local Denial of Service (DoS)
                                29 May 2017

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           HPE Network Products
Publisher:         Hewlett-Packard
Operating System:  Network Appliance
Impact/Access:     Modify Arbitrary Files -- Remote/Unauthenticated
                   Denial of Service      -- Remote/Unauthenticated
Resolution:        Patch/Upgrade
CVE Names:         CVE-2015-8158 CVE-2015-8138 CVE-2015-7979
                   CVE-2015-7975 CVE-2015-7974 CVE-2015-7973

Reference:         ASB-2016.0074
                   ASB-2016.0046
                   ESB-2016.0749
                   ESB-2016.0457
                   ESB-2016.0177

Original Bulletin: 
   https://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbhf03750en_us

- --------------------------BEGIN INCLUDED TEXT--------------------

HPESBHF03750 rev.1 - HPE Network Products including Comware 5, Comware 7 and 
VCX running NTP, Remote Denial of Service (DoS), Unauthorized Modification, 
Local Denial of Service (DoS)

SUPPORT COMMUNICATION - SECURITY BULLETIN

Document ID: hpesbhf03750en_us

Version: 1

HPESBHF03750 rev.1 - HPE Network Products including Comware 5, Comware 7 and 
VCX running NTP, Remote Denial of Service (DoS), Unauthorized Modification,
Local Denial of Service (DoS)

NOTICE: The information in this Security Bulletin should be acted upon as 
soon as possible.

Release Date: 2017-05-26

Last Updated: 2017-05-25

Potential Security Impact: Local: Denial of Service (DoS); Remote: Denial of 
Service (DoS), Unauthorized Modification

Source: Hewlett Packard Enterprise, HPE Product Security Response Team

VULNERABILITY SUMMARY

Potential security vulnerabilities with NTP have been addressed for HPE 
network products including Comware 5, Comware 7 and VCX. The vulnerabilities
could be remotely exploited resulting in Denial of Service (DoS) or 
unauthorized modification, or locally exploited resulting in Denial of 
Service (DoS).

References:

    CVE-2015-7973 - Remote unauthorized modification, Denial of Service (DoS)
    CVE-2015-7974 - Remote unauthorized modification
    CVE-2015-7975 - Local Denial of Service (DoS)
    CVE-2015-7979 - Remote Denial of Service (DoS)
    CVE-2015-8138 - Remote unauthorized modification
    CVE-2015-8158 - Remote Denial of Service (DoS)

SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed.

    Comware v5 (CW5) Products All versions - Please refer to the RESOLUTION
    below for a list of updated products.

    Comware v7 (CW7) Products All versions - Please refer to the RESOLUTION 
    below for a list of updated products.

    VCX Products All versions - Please refer to the RESOLUTION below for a 
    list of updated products.

BACKGROUND
CVSS Version 3.0 and Version 2.0 Base Metrics


Reference	V3 Vector					V3 Base Score	V2 Vector			V2 Base Score
CVE-2015-7973	CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L	6.5		(AV:N/AC:M/Au:N/C:N/I:P/A:P)	5.8
CVE-2015-7974	CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N	3.1		(AV:N/AC:H/Au:S/C:N/I:P/A:N)	2.1
CVE-2015-7975	CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L	4.0		(AV:L/AC:L/Au:N/C:N/I:N/A:P)	2.1
CVE-2015-7979	CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L	5.3		(AV:N/AC:L/Au:N/C:N/I:N/A:P)	5.0
CVE-2015-8138	CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N	5.3		(AV:N/AC:L/Au:N/C:N/I:P/A:N)	5.0
CVE-2015-8158	CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L	5.3		(AV:N/AC:M/Au:N/C:N/I:N/A:P)	4.3

Information on CVSS is documented in HPE Customer Notice: HPSN-2008-002

RESOLUTION

HPE has made the following software updates available to resolve the 
vulnerabilities in the Comware and VCX products running NTP.

COMWARE 5 Products

    A6600 (Comware 5) - Version: R3303P31
        HP Network Products
            JC165A HP 6600 RPE-X1 Router Module
            JC177A HP 6608 Router
            JC177B HP 6608 Router Chassis
            JC178A HP 6604 Router Chassis
            JC178B HP 6604 Router Chassis
            JC496A HP 6616 Router Chassis
            JC566A HP 6600 RSE-X1 Router Main Processing Unit
            JG780A HP 6600 RSE-X1 TAA-compliant Main Processing Unit
            JG781A HP 6600 RPE-X1 TAA-compliant Main Processing Unit
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    HSR6602 (Comware 5) - Version: R3303P31
        HP Network Products
            JC176A HP 6602 Router Chassis
            JG353A HP HSR6602-G Router
            JG354A HP HSR6602-XG Router
            JG355A HP 6600 MCP-X1 Router Main Processing Unit
            JG356A HP 6600 MCP-X2 Router Main Processing Unit
            JG776A HP HSR6602-G TAA-compliant Router
            JG777A HP HSR6602-XG TAA-compliant Router
            JG778A HP 6600 MCP-X2 Router TAA-compliant Main Processing Unit
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    HSR6800 (Comware 5) - Version: R3303P31
        HP Network Products
            JG361A HP HSR6802 Router Chassis
            JG361B HP HSR6802 Router Chassis
            JG362A HP HSR6804 Router Chassis
            JG362B HP HSR6804 Router Chassis
            JG363A HP HSR6808 Router Chassis
            JG363B HP HSR6808 Router Chassis
            JG364A HP HSR6800 RSE-X2 Router Main Processing Unit
            JG779A HP HSR6800 RSE-X2 Router TAA-compliant Main Processing Unit
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    MSR20 (Comware 5) - Version: R2516P06
        HP Network Products
            JD432A HP A-MSR20-21 Router
            JD662A HP MSR20-20 Router
            JD663A HP A-MSR20-21 Router
            JD663B HP MSR20-21 Router
            JD664A HP MSR20-40 Router
            JF228A HP MSR20-40 Router
            JF283A HP MSR20-20 Router
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    MSR20-1X (Comware 5) - Version: R2516P06
        HP Network Products
            JD431A HP MSR20-10 Router
            JD667A HP MSR20-15 IW Multi-Service Router
            JD668A HP MSR20-13 Multi-Service Router
            JD669A HP MSR20-13 W Multi-Service Router
            JD670A HP MSR20-15 A Multi-Service Router
            JD671A HP MSR20-15 AW Multi-Service Router
            JD672A HP MSR20-15 I Multi-Service Router
            JD673A HP MSR20-11 Multi-Service Router
            JD674A HP MSR20-12 Multi-Service Router
            JD675A HP MSR20-12 W Multi-Service Router
            JD676A HP MSR20-12 T1 Multi-Service Router
            JF236A HP MSR20-15-I Router
            JF237A HP MSR20-15-A Router
            JF238A HP MSR20-15-I-W Router
            JF239A HP MSR20-11 Router
            JF240A HP MSR20-13 Router
            JF241A HP MSR20-12 Router
            JF806A HP MSR20-12-T Router
            JF807A HP MSR20-12-W Router
            JF808A HP MSR20-13-W Router
            JF809A HP MSR20-15-A-W Router
            JF817A HP MSR20-15 Router
            JG209A HP MSR20-12-T-W Router (NA)
            JG210A HP MSR20-13-W Router (NA)
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    MSR 30 (Comware 5) - Version: R2516
        HP Network Products
            JD654A HP MSR30-60 POE Multi-Service Router
            JD657A HP MSR30-40 Multi-Service Router
            JD658A HP MSR30-60 Multi-Service Router
            JD660A HP MSR30-20 POE Multi-Service Router
            JD661A HP MSR30-40 POE Multi-Service Router
            JD666A HP MSR30-20 Multi-Service Router
            JF229A HP MSR30-40 Router
            JF230A HP MSR30-60 Router
            JF232A HP RTMSR3040-AC-OVSAS-H3
            JF235A HP MSR30-20 DC Router
            JF284A HP MSR30-20 Router
            JF287A HP MSR30-40 DC Router
            JF801A HP MSR30-60 DC Router
            JF802A HP MSR30-20 PoE Router
            JF803A HP MSR30-40 PoE Router
            JF804A HP MSR30-60 PoE Router
            JG728A HP MSR30-20 TAA-compliant DC Router
            JG729A HP MSR30-20 TAA-compliant Router
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    MSR 30-16 (Comware 5) - Version: R2516P06
        HP Network Products
            JD659A HP MSR30-16 POE Multi-Service Router
            JD665A HP MSR30-16 Multi-Service Router
            JF233A HP MSR30-16 Router
            JF234A HP MSR30-16 PoE Router,
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    MSR 30-1X (Comware 5) - Version: R2516P06
        HP Network Products
            JF800A HP MSR30-11 Router
            JF816A HP MSR30-10 2 FE /2 SIC /1 MIM MS Rtr
            JG182A HP MSR30-11E Router
            JG183A HP MSR30-11F Router
            JG184A HP MSR30-10 DC Router
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    MSR 50 (Comware 5) - Version: R2516P06
        HP Network Products
            JD433A HP MSR50-40 Router
            JD653A HP MSR50 Processor Module
            JD655A HP MSR50-40 Multi-Service Router
            JD656A HP MSR50-60 Multi-Service Router
            JF231A HP MSR50-60 Router
            JF285A HP MSR50-40 DC Router
            JF640A HP MSR50-60 Rtr Chassis w DC PwrSupply
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    MSR 50-G2 (Comware 5) - Version: R2516P06
        HP Network Products
            JD429A HP MSR50 G2 Processor Module
            JD429B HP MSR50 G2 Processor Module
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    MSR 9XX (Comware 5) - Version: R2516P06
        HP Network Products
            JF812A HP MSR900 Router
            JF813A HP MSR920 Router
            JF814A HP MSR900-W Router
            JF815A HP MSR920 2FEWAN/8FELAN/.11 b/g Rtr
            JG207A HP MSR900-W Router (NA)
            JG208A HP MSR920-W Router (NA)
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    MSR 93X (Comware 5) - Version: R2516P06
        HP Network Products
            JG511A HP MSR930 Router
            JG511B HP MSR930 Router
            JG512A HP MSR930 Wireless Router
            JG513A HP MSR930 3G Router
            JG513B HP MSR930 3G Router
            JG514A HP MSR931 Router
            JG514B HP MSR931 Router
            JG515A HP MSR931 3G Router
            JG516A HP MSR933 Router
            JG517A HP MSR933 3G Router
            JG518A HP MSR935 Router
            JG518B HP MSR935 Router
            JG519A HP MSR935 Wireless Router
            JG520A HP MSR935 3G Router
            JG531A HP MSR931 Dual 3G Router
            JG531B HP MSR931 Dual 3G Router
            JG596A HP MSR930 4G LTE/3G CDMA Router
            JG597A HP MSR936 Wireless Router
            JG665A HP MSR930 4G LTE/3G WCDMA Global Router
            JG704A HP MSR930 4G LTE/3G WCDMA ATT Router
            JH009A HP MSR931 Serial (TI) Router
            JH010A HP MSR933 G.SHDSL (TI) Router
            JH011A HP MSR935 ADSL2+ (TI) Router
            JH012A HP MSR930 Wireless 802.11n (NA) Router
            JH012B HP MSR930 Wireless 802.11n (NA) Router
            JH013A HP MSR935 Wireless 802.11n (NA) Router
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    MSR1000 (Comware 5) - Version: R2516P06
        HP Network Products
            JG732A HP MSR1003-8 AC Router
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    12500 (Comware 5) - Version: R1829P03
        HP Network Products
            JC072B HP 12500 Main Processing Unit
            JC085A HP A12518 Switch Chassis
            JC086A HP A12508 Switch Chassis
            JC652A HP 12508 DC Switch Chassis
            JC653A HP 12518 DC Switch Chassis
            JC654A HP 12504 AC Switch Chassis
            JC655A HP 12504 DC Switch Chassis
            JC808A HP 12500 TAA Main Processing Unit
            JF430A HP A12518 Switch Chassis
            JF430B HP 12518 Switch Chassis
            JF430C HP 12518 AC Switch Chassis
            JF431A HP A12508 Switch Chassis
            JF431B HP 12508 Switch Chassis
            JF431C HP 12508 AC Switch Chassis
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    9500E (Comware 5) - Version: R1829P03
        HP Network Products
            JC124A HP A9508 Switch Chassis
            JC124B HP 9505 Switch Chassis
            JC125A HP A9512 Switch Chassis
            JC125B HP 9512 Switch Chassis
            JC474A HP A9508-V Switch Chassis
            JC474B HP 9508-V Switch Chassis
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    10500 (Comware 5) - Version: R1210P03
        HP Network Products
            JC611A HP 10508-V Switch Chassis
            JC612A HP 10508 Switch Chassis
            JC613A HP 10504 Switch Chassis
            JC614A HP 10500 Main Processing Unit
            JC748A HP 10512 Switch Chassis
            JG375A HP 10500 TAA-compliant Main Processing Unit
            JG820A HP 10504 TAA-compliant Switch Chassis
            JG821A HP 10508 TAA-compliant Switch Chassis
            JG822A HP 10508-V TAA-compliant Switch Chassis
            JG823A HP 10512 TAA-compliant Switch Chassis
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    7500 (Comware 5) - Version: R6710P03
        HP Network Products
            JC666A HP 7503-S 144Gbps Fabric/MPU with PoE Upgradable 20-port Gig-T/4-port GbE Combo
            JC697A HP 7502 TAA-compliant Main Processing Unit
            JC698A HP 7503-S 144Gbps TAA Fabric / MPU with 16 GbE SFP Ports and 8 GbE Combo Ports
            JC699A HP 7500 384Gbps TAA-compliant Fabric / MPU with 2 10GbE XFP Ports
            JC700A HP 7500 384Gbps TAA-compliant Fabric / Main Processing Unit
            JC701A HP 7500 768Gbps TAA-compliant Fabric / Main Processing Unit
            JD193A HP 7500 384Gbps Fabric Module with 2 XFP Ports
            JD193B HP 7500 384Gbps Fabric Module with 2 XFP Ports
            JD194A HP 7500 384Gbps Fabric Module
            JD194B HP 7500 384Gbps Fabric Module
            JD195A HP 7500 384Gbps Advanced Fabric Module
            JD196A HP 7502 Fabric Module
            JD220A HP 7500 768Gbps Fabric Module
            JD224A HP 7500 384Gbps Fabric Module with 12 SFP Ports
            JD238A HP 7510 Switch Chassis
            JD238B HP 7510 Switch Chassis
            JD239A HP 7506 Switch Chassis
            JD239B HP 7506 Switch Chassis
            JD240A HP 7503 Switch Chassis
            JD240B HP 7503 Switch Chassis
            JD241A HP 7506-V Switch Chassis
            JD241B HP 7506-V Switch Chassis
            JD242A HP 7502 Switch Chassis
            JD242B HP 7502 Switch Chassis
            JD243A HP 7503-S Switch Chassis with 1 Fabric Slot
            JD243B HP 7503-S Switch Chassis with 1 Fabric Slot
            JE164A HP E7902 Switch Chassis
            JE165A HP E7903 Switch Chassis
            JE166A HP E7903 1 Fabric Slot Switch Chassis
            JE167A HP E7906 Switch Chassis
            JE168A HP E7906 Vertical Switch Chassis
            JE169A HP E7910 Switch Chassis
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    6125G/XG Blade Switch - Version: R2112P06
        HP Network Products
            737220-B21 HP 6125G Blade Switch with TAA
            737226-B21 HP 6125G/XG Blade Switch with TAA
            658250-B21 HP 6125G/XG Blade Switch Opt Kit
            658247-B21 HP 6125G Blade Switch Opt Kit
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    5800 (Comware 5) - Version: R1810P07
        HP Network Products
            JC099A HP 5800-24G-PoE Switch
            JC099B HP 5800-24G-PoE+ Switch
            JC100A HP 5800-24G Switch
            JC100B HP 5800-24G Switch
            JC101A HP 5800-48G Switch with 2 Slots
            JC101B HP 5800-48G-PoE+ Switch with 2 Interface Slots
            JC103A HP 5800-24G-SFP Switch
            JC103B HP 5800-24G-SFP Switch with 1 Interface Slot
            JC104A HP 5800-48G-PoE Switch
            JC104B HP 5800-48G-PoE+ Switch with 1 Interface Slot
            JC105A HP 5800-48G Switch
            JC105B HP 5800-48G Switch with 1 Interface Slot
            JG254A HP 5800-24G-PoE+ TAA-compliant Switch
            JG254B HP 5800-24G-PoE+ TAA-compliant Switch
            JG255A HP 5800-24G TAA-compliant Switch
            JG255B HP 5800-24G TAA-compliant Switch
            JG256A HP 5800-24G-SFP TAA-compliant Switch with 1 Interface Slot
            JG256B HP 5800-24G-SFP TAA-compliant Switch with 1 Interface Slot
            JG257A HP 5800-48G-PoE+ TAA-compliant Switch with 1 Interface Slot
            JG257B HP 5800-48G-PoE+ TAA-compliant Switch with 1 Interface Slot
            JG258A HP 5800-48G TAA-compliant Switch with 1 Interface Slot
            JG258B HP 5800-48G TAA-compliant Switch with 1 Interface Slot
            JG225A HP 5800AF-48G Switch
            JG225B HP 5800AF-48G Switch
            JG242A HP 5800-48G-PoE+ TAA-compliant Switch with 2 Interface Slots
            JG242B HP 5800-48G-PoE+ TAA-compliant Switch with 2 Interface
            JG243A HP 5820-24XG-SFP+ TAA-compliant Switch
            JG243B HP 5820-24XG-SFP+ TAA-compliant Switch
            JG259A HP 5820X-14XG-SFP+ TAA-compliant Switch with 2 Interface Slots & 1 OAA Slot
            JG259B HP 5820-14XG-SFP+ TAA-compliant Switch with 2 Interface Slots and 1 OAA Slot
            JC106A HP 5820-14XG-SFP+ Switch with 2 Slots
            JC106B HP 5820-14XG-SFP+ Switch with 2 Interface Slots & 1 OAA Slot
            JG219A HP 5820AF-24XG Switch
            JG219B HP 5820AF-24XG Switch
            JC102A HP 5820-24XG-SFP+ Switch
            JC102B HP 5820-24XG-SFP+ Switch
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    5500 HI (Comware 5) - Version: R5501P28
        HP Network Products
            JG311A HP 5500-24G-4SFP HI Switch with 2 Interface Slots
            JG312A HP 5500-48G-4SFP HI Switch with 2 Interface Slots
            JG541A HP 5500-24G-PoE+-4SFP HI Switch with 2 Interface Slots
            JG542A HP 5500-48G-PoE+-4SFP HI Switch with 2 Interface Slots
            JG543A HP 5500-24G-SFP HI Switch with 2 Interface Slots
            JG679A HP 5500-24G-PoE+-4SFP HI TAA-compliant Switch with 2 Interface Slots
            JG680A HP 5500-48G-PoE+-4SFP HI TAA-compliant Switch with 2 Interface Slots
            JG681A HP 5500-24G-SFP HI TAA-compliant Switch with 2 Interface Slots
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    5500 EI (Comware 5) - Version: R2221P30
        HP Network Products
            JD373A HP 5500-24G DC EI Switch
            JD374A HP 5500-24G-SFP EI Switch
            JD375A HP 5500-48G EI Switch
            JD376A HP 5500-48G-PoE EI Switch
            JD377A HP 5500-24G EI Switch
            JD378A HP 5500-24G-PoE EI Switch
            JD379A HP 5500-24G-SFP DC EI Switch
            JG240A HP 5500-48G-PoE+ EI Switch with 2 Interface Slots
            JG241A HP 5500-24G-PoE+ EI Switch with 2 Interface Slots
            JG249A HP 5500-24G-SFP EI TAA-compliant Switch with 2 Interface
            JG250A HP 5500-24G EI TAA-compliant Switch with 2 Interface Slots
            JG251A HP 5500-48G EI TAA-compliant Switch with 2 Interface Slots
            JG252A HP 5500-24G-PoE+ EI TAA-compliant Switch with 2 Interface Slots
            JG253A HP 5500-48G-PoE+ EI TAA-compliant Switch with 2 Interface Slots
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    4800G (Comware 5) - Version: R2221P30
        HP Network Products
            JD007A HP 4800-24G Switch
            JD008A HP 4800-24G-PoE Switch
            JD009A HP 4800-24G-SFP Switch
            JD010A HP 4800-48G Switch
            JD011A HP 4800-48G-PoE Switch
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    5500SI (Comware 5) - Version: R2221P30
        HP Network Products
            JD369A HP 5500-24G SI Switch
            JD370A HP 5500-48G SI Switch
            JD371A HP 5500-24G-PoE SI Switch
            JD372A HP 5500-48G-PoE SI Switch
            JG238A HP 5500-24G-PoE+ SI Switch with 2 Interface Slots
            JG239A HP 5500-48G-PoE+ SI Switch with 2 Interface Slots
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    4500G (Comware 5) - Version: R2221P30
        HP Network Products
            JF428A HP 4510-48G Switch
            JF847A HP 4510-24G Switch
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    5120 EI (Comware 5) - Version: R2221P30
        HP Network Products
            JE066A HP 5120-24G EI Switch
            JE067A HP 5120-48G EI Switch
            JE068A HP 5120-24G EI Switch with 2 Interface Slots
            JE069A HP 5120-48G EI Switch with 2 Interface Slots
            JE070A HP 5120-24G-PoE EI 2-slot Switch
            JE071A HP 5120-48G-PoE EI 2-slot Switch
            JG236A HP 5120-24G-PoE+ EI Switch with 2 Interface Slots
            JG237A HP 5120-48G-PoE+ EI Switch with 2 Interface Slots
            JG245A HP 5120-24G EI TAA-compliant Switch with 2 Interface Slots
            JG246A HP 5120-48G EI TAA-compliant Switch with 2 Interface Slots
            JG247A HP 5120-24G-PoE+ EI TAA-compliant Switch with 2 Slots
            JG248A HP 5120-48G-PoE+ EI TAA-compliant Switch with 2 Slots
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    4210G (Comware 5) - Version: R2221P30
        HP Network Products
            JF844A HP 4210-24G Switch
            JF845A HP 4210-48G Switch
            JF846A HP 4210-24G-PoE Switch
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    5120 SI (Comware 5) - Version: R1518P03
        HP Network Products
            JE072A HP 5120-48G SI Switch
            JE072B HPE 5120 48G SI Switch
            JE073A HP 5120-16G SI Switch
            JE073B HPE 5120 16G SI Switch
            JE074A HP 5120-24G SI Switch
            JE074B HPE 5120 24G SI Switch
            JG091A HP 5120-24G-PoE+ (370W) SI Switch
            JG091B HPE 5120 24G PoE+ (370W) SI Switch
            JG092A HP 5120-24G-PoE+ (170W) SI Switch
            JG309B HPE 5120 8G PoE+ (180W) SI Switch
            JG310B HPE 5120 8G PoE+ (65W) SI Switch
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    3610 (Comware 5) - Version: R5319P16
        HP Network Products
            JD335A HP 3610-48 Switch
            JD336A HP 3610-24-4G-SFP Switch
            JD337A HP 3610-24-2G-2G-SFP Switch
            JD338A HP 3610-24-SFP Switch
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    3600V2 (Comware 5) - Version: R2111P04
        HP Network Products
            JG299A HP 3600-24 v2 EI Switch
            JG299B HP 3600-24 v2 EI Switch
            JG300A HP 3600-48 v2 EI Switch
            JG300B HP 3600-48 v2 EI Switch
            JG301A HP 3600-24-PoE+ v2 EI Switch
            JG301B HP 3600-24-PoE+ v2 EI Switch
            JG301C HP 3600-24-PoE+ v2 EI Switch
            JG302A HP 3600-48-PoE+ v2 EI Switch
            JG302B HP 3600-48-PoE+ v2 EI Switch
            JG302C HP 3600-48-PoE+ v2 EI Switch
            JG303A HP 3600-24-SFP v2 EI Switch
            JG303B HP 3600-24-SFP v2 EI Switch
            JG304A HP 3600-24 v2 SI Switch
            JG304B HP 3600-24 v2 SI Switch
            JG305A HP 3600-48 v2 SI Switch
            JG305B HP 3600-48 v2 SI Switch
            JG306A HP 3600-24-PoE+ v2 SI Switch
            JG306B HP 3600-24-PoE+ v2 SI Switch
            JG306C HP 3600-24-PoE+ v2 SI Switch
            JG307A HP 3600-48-PoE+ v2 SI Switch
            JG307B HP 3600-48-PoE+ v2 SI Switch
            JG307C HP 3600-48-PoE+ v2 SI Switch
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    3100V2 (Comware 5) - Version: R5213P03
        HP Network Products
            JD313B HPE 3100 24 PoE v2 EI Switch
            JD318B HPE 3100 8 v2 EI Switch
            JD319B HPE 3100 16 v2 EI Switch
            JD320B HPE 3100 24 v2 EI Switch
            JG221A HPE 3100 8 v2 SI Switch
            JG222A HPE 3100 16 v2 SI Switch
            JG223A HPE 3100 24 v2 SI Switch
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    HP870 (Comware 5) - Version: R2607P55
        HP Network Products
            JG723A HP 870 Unified Wired-WLAN Appliance
            JG725A HP 870 Unified Wired-WLAN TAA-compliant Appliance
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    HP850 (Comware 5) - Version: R2607P55
        HP Network Products
            JG722A HP 850 Unified Wired-WLAN Appliance
            JG724A HP 850 Unified Wired-WLAN TAA-compliant Appliance
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    HP830 (Comware 5) - Version: R3507P55
        HP Network Products
            JG640A HP 830 24-Port PoE+ Unified Wired-WLAN Switch
            JG641A HP 830 8-port PoE+ Unified Wired-WLAN Switch
            JG646A HP 830 24-Port PoE+ Unified Wired-WLAN TAA-compliant Switch
            JG647A HP 830 8-Port PoE+ Unified Wired-WLAN TAA-compliant
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    HP6000 (Comware 5) - Version: R2507P55
        HP Network Products
            JG639A HP 10500/7500 20G Unified Wired-WLAN Module
            JG645A HP 10500/7500 20G Unified Wired-WLAN TAA-compliant Module
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    WX5004-EI (Comware 5) - Version: R2507P55
        HP Network Products
            JD447B HP WX5002 Access Controller
            JD448A HP WX5004 Access Controller
            JD448B HP WX5004 Access Controller
            JD469A HP WX5004 Access Controller
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    SecBlade FW (Comware 5) - Version: R3181P09
        HP Network Products
            JC635A HP 12500 VPN Firewall Module
            JD245A HP 9500 VPN Firewall Module
            JD249A HP 10500/7500 Advanced VPN Firewall Module
            JD250A HP 6600 Firewall Processing Router Module
            JD251A HP 8800 Firewall Processing Module
            JD255A HP 5820 VPN Firewall Module
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    F1000-E (Comware 5) - Version: TBD still fixing
        HP Network Products
            JD272A HP F1000-E VPN Firewall Appliance
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    F1000-A-EI (Comware 5) - Version: TBD still fixing
        HP Network Products
            JG214A HP F1000-A-EI VPN Firewall Appliance
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    F1000-S-EI (Comware 5) - Version: TBD still fixing
        HP Network Products
            JG213A HP F1000-S-EI VPN Firewall Appliance
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    F1000-A-EI/F1000-S-EI - Version: R3734P10
        HP Network Products
            JD272A HP F1000-E VPN Firewall Appliance
            JG214A HP F1000-A-EI VPN Firewall Appliance
            JG213A HP F1000-S-EI VPN Firewall Appliance
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    F5000-A (Comware 5) - Version: F3210P27
        HP Network Products
            JD259A HP A5000-A5 VPN Firewall Chassis
            JG215A HP F5000 Firewall Main Processing Unit
            JG216A HP F5000 Firewall Standalone Chassis
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    U200S and CS (Comware 5) - Version: F5123P34
        HP Network Products
            JD273A HP U200-S UTM Appliance
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    U200A and M (Comware 5) - Version: F5123P34
        HP Network Products
            JD275A HP U200-A UTM Appliance
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    F5000-C/S (Comware 5) - Version: TBD still fixing
        HP Network Products
            JG650A HP F5000-C VPN Firewall Appliance
            JG370A HP F5000-S VPN Firewall Appliance
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    SecBlade III (Comware 5) - Version: TBD still fixing
        HP Network Products
            JG371A HP 12500 20Gbps VPN Firewall Module
            JG372A HP 10500/11900/7500 20Gbps VPN Firewall Module
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    6600 RSE RU (Comware 5 Low Encryption SW) - Version: R3303P31
        HP Network Products
            JC177A HP 6608 Router
            JC177B HP 6608 Router Chassis
            JC178A HP 6604 Router Chassis
            JC178B HP 6604 Router Chassis
            JC496A HP 6616 Router Chassis
            JC566A HP 6600 RSE-X1 Router Main Processing Unit
            JG780A HP 6600 RSE-X1 TAA-compliant Main Processing Unit
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    6600 RPE RU (Comware 5 Low Encryption SW) - Version: R3303P31
        HP Network Products
            JC165A HP 6600 RPE-X1 Router Module
            JC177A HP 6608 Router
            JC177B HPE FlexNetwork 6608 Router Chassis
            JC178A HPE FlexNetwork 6604 Router Chassis
            JC178B HPE FlexNetwork 6604 Router Chassis
            JC496A HPE FlexNetwork 6616 Router Chassis
            JG781A HP 6600 RPE-X1 TAA-compliant Main Processing Unit
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    6602 RU (Comware 5 Low Encryption SW) - Version: R3303P31
        HP Network Products
            JC176A HP 6602 Router Chassis
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    HSR6602 RU (Comware 5 Low Encryption SW) - Version: R3303P31
        HP Network Products
            JC177A HP 6608 Router
            JC177B HP 6608 Router Chassis
            JC178A HP 6604 Router Chassis
            JC178B HP 6604 Router Chassis
            JC496A HP 6616 Router Chassis
            JG353A HP HSR6602-G Router
            JG354A HP HSR6602-XG Router
            JG355A HP 6600 MCP-X1 Router Main Processing Unit
            JG356A HP 6600 MCP-X2 Router Main Processing Unit
            JG776A HP HSR6602-G TAA-compliant Router
            JG777A HP HSR6602-XG TAA-compliant Router
            JG778A HP 6600 MCP-X2 Router TAA-compliant Main Processing Unit
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    HSR6800 RU (Comware 5 Low Encryption SW) - Version: R3303P31
        HP Network Products
            JG361A HP HSR6802 Router Chassis
            JG361B HP HSR6802 Router Chassis
            JG362A HP HSR6804 Router Chassis
            JG362B HP HSR6804 Router Chassis
            JG363A HP HSR6808 Router Chassis
            JG363B HP HSR6808 Router Chassis
            JG364A HP HSR6800 RSE-X2 Router Main Processing Unit
            JG779A HP HSR6800 RSE-X2 Router TAA-compliant Main Processing Unit
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    SMB1910 (Comware 5) - Version: R1115
        HP Network Products
            JG540A HP 1910-48 Switch
            JG539A HP 1910-24-PoE+ Switch
            JG538A HP 1910-24 Switch
            JG537A HP 1910-8 -PoE+ Switch
            JG536A HP 1910-8 Switch
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    SMB1920 (Comware 5) - Version: R1114
        HP Network Products
            JG928A HP 1920-48G-PoE+ (370W) Switch
            JG927A HP 1920-48G Switch
            JG926A HP 1920-24G-PoE+ (370W) Switch
            JG925A HP 1920-24G-PoE+ (180W) Switch
            JG924A HP 1920-24G Switch
            JG923A HP 1920-16G Switch
            JG922A HP 1920-8G-PoE+ (180W) Switch
            JG921A HP 1920-8G-PoE+ (65W) Switch
            JG920A HP 1920-8G Switch
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    V1910 (Comware 5) - Version: R1518P03
        HP Network Products
            JE005A HP 1910-16G Switch
            JE006A HP 1910-24G Switch
            JE007A HP 1910-24G-PoE (365W) Switch
            JE008A HP 1910-24G-PoE(170W) Switch
            JE009A HP 1910-48G Switch
            JG348A HP 1910-8G Switch
            JG349A HP 1910-8G-PoE+ (65W) Switch
            JG350A HP 1910-8G-PoE+ (180W) Switch
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    SMB 1620 (Comware 5) - Version: R1112
        HP Network Products
            JG914A HP 1620-48G Switch
            JG913A HP 1620-24G Switch
            JG912A HP 1620-8G Switch
        CVEs
            CVE-2015-7973
            CVE-2015-7974
    NJ5000 - Version: R1108
        HP Network Products
            JH237A HPE FlexNetwork NJ5000 5G PoE+ Walljack
        CVEs
            CVE-2015-7973
            CVE-2015-7974

COMWARE 7 Products

    12500 (Comware 7) - Version: R7377P02
        HP Network Products
            JC072B HP 12500 Main Processing Unit
            JC085A HP A12518 Switch Chassis
            JC086A HP A12508 Switch Chassis
            JC652A HP 12508 DC Switch Chassis
            JC653A HP 12518 DC Switch Chassis
            JC654A HP 12504 AC Switch Chassis
            JC655A HP 12504 DC Switch Chassis
            JF430A HP A12518 Switch Chassis
            JF430B HP 12518 Switch Chassis
            JF430C HP 12518 AC Switch Chassis
            JF431A HP A12508 Switch Chassis
            JF431B HP 12508 Switch Chassis
            JF431C HP 12508 AC Switch Chassis
            JG497A HP 12500 MPU w/Comware V7 OS
            JG782A HP FF 12508E AC Switch Chassis
            JG783A HP FF 12508E DC Switch Chassis
            JG784A HP FF 12518E AC Switch Chassis
            JG785A HP FF 12518E DC Switch Chassis
            JG802A HP FF 12500E MPU
        CVEs
            CVE-2015-7973
            CVE-2015-7974
            CVE-2015-7979
            CVE-2015-8138
    10500 (Comware 7) - Version: R7184
        HP Network Products
            JC611A HP 10508-V Switch Chassis
            JC612A HP 10508 Switch Chassis
            JC613A HP 10504 Switch Chassis
            JC748A HP 10512 Switch Chassis
            JG608A HP FlexFabric 11908-V Switch Chassis
            JG609A HP FlexFabric 11900 Main Processing Unit
            JG820A HP 10504 TAA Switch Chassis
            JG821A HP 10508 TAA Switch Chassis
            JG822A HP 10508-V TAA Switch Chassis
            JG823A HP 10512 TAA Switch Chassis
            JG496A HP 10500 Type A MPU w/Comware v7 OS
            JH198A HP 10500 Type D Main Processing Unit with Comware v7 Operating System
            JH206A HP 10500 Type D TAA-compliant with Comware v7 Operating System Main Processing Unit
        CVEs
            CVE-2015-7973
            CVE-2015-7974
            CVE-2015-7979
            CVE-2015-8138
    5900 (Comware 7) - Version: R2422P02
        HP Network Products
            JC772A HP 5900AF-48XG-4QSFP+ Switch
            JG296A HP 5920AF-24XG Switch
            JG336A HP 5900AF-48XGT-4QSFP+ Switch
            JG510A HP 5900AF-48G-4XG-2QSFP+ Switch
            JG554A HP 5900AF-48XG-4QSFP+ TAA Switch
            JG555A HP 5920AF-24XG TAA Switch
            JG838A HP FF 5900CP-48XG-4QSFP+ Switch
            JH036A HP FlexFabric 5900CP 48XG 4QSFP+ TAA-Compliant
            JH037A HP 5900AF 48XGT 4QSFP+ TAA-Compliant Switch
            JH038A HP 5900AF 48G 4XG 2QSFP+ TAA-Compliant
        CVEs
            CVE-2015-7973
            CVE-2015-7974
            CVE-2015-7979
            CVE-2015-8138
    MSR1000 (Comware 7) - Version: R0306P52
        HP Network Products
            JG875A HP MSR1002-4 AC Router
            JH060A HP MSR1003-8S AC Router
        CVEs
            CVE-2015-7973
            CVE-2015-7974
            CVE-2015-7979
            CVE-2015-8138
    MSR2000 (Comware 7) - Version: R0306P52
        HP Network Products
            JG411A HP MSR2003 AC Router
            JG734A HP MSR2004-24 AC Router
            JG735A HP MSR2004-48 Router
            JG866A HP MSR2003 TAA-compliant AC Router
        CVEs
            CVE-2015-7973
            CVE-2015-7974
            CVE-2015-7979
            CVE-2015-8138
    MSR3000 (Comware 7) - Version: R0306P52
        HP Network Products
            JG404A HP MSR3064 Router
            JG405A HP MSR3044 Router
            JG406A HP MSR3024 AC Router
            JG407A HP MSR3024 DC Router
            JG408A HP MSR3024 PoE Router
            JG409A HP MSR3012 AC Router
            JG410A HP MSR3012 DC Router
            JG861A HP MSR3024 TAA-compliant AC Router
        CVEs
            CVE-2015-7973
            CVE-2015-7974
            CVE-2015-7979
            CVE-2015-8138
    MSR4000 (Comware 7) - Version: R0306P52
        HP Network Products
            JG402A HP MSR4080 Router Chassis
            JG403A HP MSR4060 Router Chassis
            JG412A HP MSR4000 MPU-100 Main Processing Unit
            JG869A HP MSR4000 TAA-compliant MPU-100 Main Processing Unit
        CVEs
            CVE-2015-7973
            CVE-2015-7974
            CVE-2015-7979
            CVE-2015-8138
    VSR (Comware 7) - Version: E0324
        HP Network Products
            JG810AAE HP VSR1001 Virtual Services Router 60 Day Evaluation Software
            JG811AAE HP VSR1001 Comware 7 Virtual Services Router
            JG812AAE HP VSR1004 Comware 7 Virtual Services Router
            JG813AAE HP VSR1008 Comware 7 Virtual Services Router
        CVEs
            CVE-2015-7973
            CVE-2015-7974
            CVE-2015-7979
            CVE-2015-8138
    7900 (Comware 7) - Version: R2152
        HP Network Products
            JG682A HP FlexFabric 7904 Switch Chassis
            JG841A HP FlexFabric 7910 Switch Chassis
            JG842A HP FlexFabric 7910 7.2Tbps Fabric / Main Processing Unit
            JH001A HP FlexFabric 7910 2.4Tbps Fabric / Main Processing Unit
            JH122A HP FlexFabric 7904 TAA-compliant Switch Chassis
            JH123A HP FlexFabric 7910 TAA-compliant Switch Chassis
            JH124A HP FlexFabric 7910 7.2Tbps TAA-compliant Fabric/Main Processing Unit
            JH125A HP FlexFabric 7910 2.4Tbps TAA-compliant Fabric/Main Processing Unit
        CVEs
            CVE-2015-7973
            CVE-2015-7974
            CVE-2015-7979
            CVE-2015-8138
    5130 (Comware 7) - Version: R3115P01
        HP Network Products
            JG932A HP 5130-24G-4SFP+ EI Switch
            JG933A HP 5130-24G-SFP-4SFP+ EI Switch
            JG934A HP 5130-48G-4SFP+ EI Switch
            JG936A HP 5130-24G-PoE+-4SFP+ (370W) EI Switch
            JG937A HP 5130-48G-PoE+-4SFP+ (370W) EI Switch
            JG938A HP 5130-24G-2SFP+-2XGT EI Switch
            JG939A HP 5130-48G-2SFP+-2XGT EI Switch
            JG940A HP 5130-24G-PoE+-2SFP+-2XGT (370W) EI Switch
            JG941A HP 5130-48G-PoE+-2SFP+-2XGT (370W) EI Switch
            JG975A HP 5130-24G-4SFP+ EI Brazil Switch
            JG976A HP 5130-48G-4SFP+ EI Brazil Switch
            JG977A HP 5130-24G-PoE+-4SFP+ (370W) EI Brazil Switch
            JG978A HP 5130-48G-PoE+-4SFP+ (370W) EI Brazil Switch
        CVEs
            CVE-2015-7973
            CVE-2015-7974
            CVE-2015-7979
            CVE-2015-8138
    6125XLG - Version: R2422P02
        HP Network Products
            711307-B21 HP 6125XLG Blade Switch
            737230-B21 HP 6125XLG Blade Switch with TAA
        CVEs
            CVE-2015-7973
            CVE-2015-7974
            CVE-2015-7979
            CVE-2015-8138
    6127XLG - Version: R2422P02
        HP Network Products
            787635-B21 HP 6127XLG Blade Switch Opt Kit
            787635-B22 HP 6127XLG Blade Switch with TAA
        CVEs
            CVE-2015-7973
            CVE-2015-7974
            CVE-2015-7979
            CVE-2015-8138
    Moonshot - Version: R2422P02
        HP Network Products
            786617-B21 - HP Moonshot-45Gc Switch Module
            704654-B21 - HP Moonshot-45XGc Switch Module
            786619-B21 - HP Moonshot-180XGc Switch Module
        CVEs
            CVE-2015-7973
            CVE-2015-7974
            CVE-2015-7979
            CVE-2015-8138
    5700 (Comware 7) - Version: R2422P02
        HP Network Products
            JG894A HP FlexFabric 5700-48G-4XG-2QSFP+ Switch
            JG895A HP FlexFabric 5700-48G-4XG-2QSFP+ TAA-compliant Switch
            JG896A HP FlexFabric 5700-40XG-2QSFP+ Switch
            JG897A HP FlexFabric 5700-40XG-2QSFP+ TAA-compliant Switch
            JG898A HP FlexFabric 5700-32XGT-8XG-2QSFP+ Switch
            JG899A HP FlexFabric 5700-32XGT-8XG-2QSFP+ TAA-compliant Switch
        CVEs
            CVE-2015-7973
            CVE-2015-7974
            CVE-2015-7979
            CVE-2015-8138
    5930 (Comware 7) - Version: R2422P02
        HP Network Products
            JG726A HP FlexFabric 5930 32QSFP+ Switch
            JG727A HP FlexFabric 5930 32QSFP+ TAA-compliant Switch
            JH178A HP FlexFabric 5930 2QSFP+ 2-slot Switch
            JH179A HP FlexFabric 5930 4-slot Switch
            JH187A HP FlexFabric 5930 2QSFP+ 2-slot TAA-compliant Switch
            JH188A HP FlexFabric 5930 4-slot TAA-compliant Switch
        CVEs
            CVE-2015-7973
            CVE-2015-7974
            CVE-2015-7979
            CVE-2015-8138
    HSR6600 (Comware 7) - Version: R7103P09
        HP Network Products
            JG353A HP HSR6602-G Router
            JG354A HP HSR6602-XG Router
            JG776A HP HSR6602-G TAA-compliant Router
            JG777A HP HSR6602-XG TAA-compliant Router
        CVEs
            CVE-2015-7973
            CVE-2015-7974
            CVE-2015-7979
            CVE-2015-8138
    HSR6800 (Comware 7) - Version: R7103P10
        HP Network Products
            JG361A HP HSR6802 Router Chassis
            JG361B HP HSR6802 Router Chassis
            JG362A HP HSR6804 Router Chassis
            JG362B HP HSR6804 Router Chassis
            JG363A HP HSR6808 Router Chassis
            JG363B HP HSR6808 Router Chassis
            JG364A HP HSR6800 RSE-X2 Router Main Processing Unit
            JG779A HP HSR6800 RSE-X2 Router TAA-compliant Main Processing
            JH075A HP HSR6800 RSE-X3 Router Main Processing Unit
        CVEs
            CVE-2015-7973
            CVE-2015-7974
            CVE-2015-7979
            CVE-2015-8138
    1950 (Comware 7) - Version: R3115P01
        HP Network Products
            JG960A HP 1950-24G-4XG Switch
            JG961A HP 1950-48G-2SFP+-2XGT Switch
            JG962A HP 1950-24G-2SFP+-2XGT-PoE+(370W) Switch
            JG963A HP 1950-48G-2SFP+-2XGT-PoE+(370W) Switch
        CVEs
            CVE-2015-7973
            CVE-2015-7974
            CVE-2015-7979
            CVE-2015-8138
    7500 (Comware 7) - Version: R7184
        HP Network Products
            JD238C HP 7510 Switch Chassis
            JD239C HP 7506 Switch Chassis
            JD240C HP 7503 Switch Chassis
            JD242C HP 7502 Switch Chassis
            JH207A HP 7500 1.2Tbps Fabric with 2-port 40GbE QSFP+ for IRF-Only Main Processing Unit
            JH208A HP 7502 Main Processing Unit
            JH209A HP 7500 2.4Tbps Fabric with 8-port 1/10GbE SFP+ and 2-port 40GbE QSFP+ Main Processing Unit
        CVEs
            CVE-2015-7973
            CVE-2015-7974
            CVE-2015-7979
            CVE-2015-8138
    5510HI (Comware 7) - Version: R1120P10
        HP Network Products
            JH145A HPE 5510 24G 4SFP+ HI 1-slot Switch
            JH146A HPE 5510 48G 4SFP+ HI 1-slot Switch
            JH147A HPE 5510 24G PoE+ 4SFP+ HI 1-slot Switch
            JH148A HPE 5510 48G PoE+ 4SFP+ HI 1-slot Switch
            JH149A HPE 5510 24G SFP 4SFP+ HI 1-slot Switch
        CVEs
            CVE-2015-7973
            CVE-2015-7974
            CVE-2015-7979
            CVE-2015-8138
    5130HI (Comware 7) - Version: R1120P10
        HP Network Products
            JH323A HPE 5130 24G 4SFP+ 1-slot HI Switch
            JH324A HPE 5130 48G 4SFP+ 1-slot HI Switch
            JH325A HPE 5130 24G PoE+ 4SFP+ 1-slot HI Switch
            JH326A HPE 5130 48G PoE+ 4SFP+ 1-slot HI Switch
        CVEs
            CVE-2015-7973
            CVE-2015-7974
            CVE-2015-7979
            CVE-2015-8138
    5940 - Version: R2508
        HP Network Products
            JH390A HPE FlexFabric 5940 48SFP+ 6QSFP28 Switch
            JH391A HPE FlexFabric 5940 48XGT 6QSFP28 Switch
            JH394A HPE FlexFabric 5940 48XGT 6QSFP+ Switch
            JH395A HPE FlexFabric 5940 48SFP+ 6QSFP+ Switch
            JH396A HPE FlexFabric 5940 32QSFP+ Switch
            JH397A HPE FlexFabric 5940 2-slot Switch
            JH398A HPE FlexFabric 5940 4-slot Switch
        CVEs
            CVE-2015-7973
            CVE-2015-7974
            CVE-2015-7979
            CVE-2015-8138
    12900E (Comware 7) - Version: R2609
        HP Network Products
            JG619A HP FlexFabric 12910 Switch AC Chassis
            JG621A HP FlexFabric 12910 Main Processing Unit
            JG632A HP FlexFabric 12916 Switch AC Chassis
            JG634A HP FlexFabric 12916 Main Processing Unit
            JH104A HP FlexFabric 12900E Main Processing Unit
            JH114A HP FlexFabric 12910 TAA-compliant Main Processing Unit
            JH263A HP FlexFabric 12904E Main Processing Unit
            JH255A HP FlexFabric 12908E Switch Chassis
            JH262A HP FlexFabric 12904E Switch Chassis
            JH113A HP FlexFabric 12910 TAA-compliant Switch AC Chassis
            JH103A HP FlexFabric 12916E Switch Chassis
        CVEs
            CVE-2015-7973
            CVE-2015-7974
            CVE-2015-7979
            CVE-2015-8138

VCX Products

    VCX - Version: 9.8.19
        HP Network Products
            J9672A HP VCX V7205 Platform w/ DL360 G7 Srvr
            J9668A HP VCX IPC V7005 Pltfrm w/ DL120 G6 Srvr
            JC517A HP VCX V7205 Platform w/DL 360 G6 Server
            JE355A HP VCX V6000 Branch Platform 9.0
            JC516A HP VCX V7005 Platform w/DL 120 G6 Server
            JC518A HP VCX Connect 200 Primry 120 G6 Server
            J9669A HP VCX IPC V7310 Pltfrm w/ DL360 G7 Srvr
            JE341A HP VCX Connect 100 Secondary
            JE252A HP VCX Connect Primary MIM Module
            JE253A HP VCX Connect Secondary MIM Module
            JE254A HP VCX Branch MIM Module
            JE355A HP VCX V6000 Branch Platform 9.0
            JD028A HP MS30-40 RTR w/VCX + T1/FXO/FXS/Mod
            JD023A HP MSR30-40 Router with VCX MIM Module
            JD024A HP MSR30-16 RTR w/VCX Ent Br Com MIM
            JD025A HP MSR30-16 RTR w/VCX + 4FXO/2FXS Mod
            JD026A HP MSR30-16 RTR w/VCX + 8FXO/4FXS Mod
            JD027A HP MSR30-16 RTR w/VCX + 8BRI/4FXS Mod
            JD029A HP MSR30-16 RTR w/VCX + E1/4BRI/4FXS
            JE340A HP VCX Connect 100 Pri Server 9.0
            JE342A HP VCX Connect 100 Sec Server 9.0
        CVEs
            CVE-2015-7975
            CVE-2015-8158

Note: Please contact HPE Technical Support if any assistance is needed
acquiring the software updates.

HISTORY
Version:1 (rev.1) - 25 May 2017 Initial release

Third Party Security Patches: Third party security patches that are to be 
installed on systems running Hewlett Packard Enterprise (HPE) software 
products should be applied in accordance with the customer's patch management 
policy.

Support: For issues about implementing the recommendations of this Security 
Bulletin, contact normal HPE Services support channel. For other issues about
the content of this Security Bulletin, send e-mail to security-alert@hpe.com.
Report: To report a potential security vulnerability for any HPE supported 
product:

    Web Form: https://www.hpe.com/info/report-security-vulnerability

    Email: security-alert@hpe.com

Subscribe: To initiate a subscription to receive future HPE Security Bulletin
alerts via Email: http://www.hpe.com/support/Subscriber_Choice

Security Bulletin Archive: A list of recently released Security Bulletins is 
available here: http://www.hpe.com/support/Security_Bulletin_Archive

Software Product Category: The Software Product Category is represented in the
title by the two characters following HPSB.

3C = 3COM
3P = 3rd Party Software
GN = HP General Software
HF = HP Hardware and Firmware
MU = Multi-Platform Software
NS = NonStop Servers
OV = OpenVMS
PV = ProCurve
ST = Storage Software
UX = HP-UX

System management and security procedures must be reviewed frequently to 
maintain system integrity. HPE is continually reviewing and enhancing the 
security features of software products to provide customers with current 
secure solutions.

"HPE is broadly distributing this Security Bulletin in order to bring to the 
attention of users of the affected HPE products the important security
information contained in this Bulletin. HPE recommends that all users 
determine the applicability of this information to their individual 
situations and take appropriate action. HPE does not warrant that this 
information is necessarily accurate or complete for all user situations and,
consequently, HPE will not be responsible for any damages resulting from user's
use or disregard of the information provided in this Bulletin. To the extent
permitted by law, HPE disclaims all warranties, either express or implied,
including the warranties of merchantability and fitness for a particular
purpose, title and non-infringement."

Copyright 2017 Hewlett Packard Enterprise Company, L.P.
Hewlett Packard Enterprise Company shall not be liable for technical or
editorial errors or omissions contained herein. The information provided is 
provided "as is" without warranty of any kind. To the extent permitted by 
law, neither HPE nor its affiliates, subcontractors or suppliers will be 
liable for incidental, special or consequential damages including downtime 
cost; lost profits; damages relating to the procurement of substitute
products or services; or damages for loss of data, or software restoration. 
The information in this document is subject to change without notice. 
Hewlett Packard Enterprise Company and the names of Hewlett Packard 
Enterprise Company products referenced herein are trademarks of Hewlett 
Packard Enterprise Company in the United States and other countries. Other
product and company names mentioned herein may be trademarks of their 
espective owners.

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        http://www.auscert.org.au/render.html?cid=1980

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBWStz6ox+lLeg9Ub1AQgt9A//Qqgj01XKY2LZbfozSuWZ9X95V3Hw83wW
Pcpk3kV1xq9vhdTmQ9MGWbAxJ12wtocEEAhijWSfyY+eDEGeKJOPKoBq0eWuIhpf
rURnX13S78lNE80GwyM+W7US/kHLUzVy27rGGKgVCSb9hte0AFVG1FuF/SXtkpAn
XXmwEds9qjMFzQG73gv6BF0aP0x+zJkG26KNFKLrktIXolq7Cjs0+bCjBKKFu1IL
8BKnvnQoM2Nb4pdkIUh2iqwfFRdZQI/GYIkMA4VD6+QWRtLOa4AmWO5uwRVAIwnx
f340vtyprV9LIbdvUpbWm/yvceBLip/s6ioZG+Fok59de6nkMEn4AaVoUc5EdEt5
llGDQQySsU7P0/btEsA4EO2tO1nmAhOZNhDm8WL2LuY90R5wh5tml2OlpHTxC4XG
GwM3Vy2TFNEOcJR5trvVwHAH5mz5XuOrlPEG0Xjw2HDcyPIk6hxZ5a7cX+nW4Bmi
/lMAgmwMIjfR0WSA/V4QPtKAal12pxYQ66hHFoqCacLk7/XspHpAd8eI8z23Jo36
TeIIFhtAHws+YW+S3heEQmM2zhiufGlyIaN6X8ZIxx8GUrUA42oUV8Tn1G6n2i9o
YG+RGsy0uXjIT3dzCoQ3HjtJoYGfLQHDW4c3ZkjKpEUH5ieUqsvQkxFQZveGA+Nx
bu9TUqATUd8=
=4K9k
-----END PGP SIGNATURE-----