HPE has reported Denial of Service (DOS) vulnerabilities affecting its servers, as caused by an ongoing Intel processor issue.

In a report published last week, HPE reports the vulnerability in certain SimpliVity servers, with Intel processors at risk of being locally exploited to allow denial of service.

Named CVE-2024-37020, the bug was first discovered in February with Intel reporting a "potential security vulnerability in the Intel Data Streaming Accelerator (Intel DSA) for some Intel Xeon Processors".

The latest flaw has been reported as affecting HPE SimpliVity 380 Gen11. HPE has provided users with updated BIOS firmware in the form of HPE SimpliVity Support Pack Gen11 (SVTSPGen11) v2025_0630 or later.

No known active exploits have been disclosed; SDxCentral has contacted HPE for further information.

The DOS vulnerability has been reported this year by Dell for its PowerEdge servers and SUSE for its Linux-based Enterprise offerings.

HPE had previously released a patch addressing the issue impacting some of its StoreEasy servers..

The Intel discovery follows recent DOS vulnerabilities found in Citrix NetScaler devices, the underlying issue of which was buffer overflow in C-based code.

Because firmware is built on this code, CISA recently recommended moving network infrastructure to memory-safe languages in June.