================================================================================ Express5800/R110k-1 System ROM U60 v1.60 (07/14/2022) ================================================================================ Software name : Express5800/R110k-1 System ROM (BIOS) update module Models : Express5800/R110k-1 Operating System : This software supports offline update and the following OS. - Windows Server(R) 2019 - Windows Server(R) 2022 - Red Hat(R) Enterprise Linux(R) 8 Target Users : See [Target Users for Update] below Type : System ROM ================================================================================ [About the software] The Express5800/R110k-1 System ROM (BIOS) update module supports the following changes in the Express5800/R110k-1 models: Enhancements and problem fixes: - Updated microcode for Processor. This version mitigates security vulnerability ofCVE-2022-21233. Intel(R) Xeon(R) E Processor Intel(R) Pentium(R) Gold Processor Series - This version mitigates a security vulnerability (CVE-2022-0778, CVE-2022-1292, CVE-2022-2068) in OpenSSL. - This version mitigates a security vulnerability (CVE-2022-27405) in FreeType library. - This version mitigates a security vulnerability (CVE-2018-25032) in zlib library. - Addressed an issue where the system fails to boot OpenShift Container Platform when Boot Mode option was set to UEFI Mode and the UEFI Optimized Boot option was set to Enabled. System Configuration > BIOS/Platform Configuration (RBSU) > Boot Options > Boot Mode System Configuration > BIOS/Platform Configuration (RBSU) > Boot Options > UEFI Optimized Boot - Addressed an issue where RAID controller names were not displayed correctly in the PCIe Device Configuration menu in RBSU or the One-Time Boot menu when the Select Language option in System Utilities was set to non-English. System Configuration > BIOS/Platform Configuration (RBSU) > PCIe Device Configuration ** Program and data included in this software ** Following program and data are included in this software. Use one of them according to the way of installation. a) Flash image for System Utilities/iLO Web User Interface firmware\U60_1.60_07_14_2022.signed.flash b) Executables for Windows(R) winx64\cp052459.exe c) RPM package for Linux(R) Linux\firmware-system-oem-u60-1.60_2022_07_14-1.1.x86_64.rpm ------------------------------------------------------------------------------- [ Target Users for Update ] This software is available for the users who use the following models with the following System ROM version. - Models to be supported 1. Express5800/R110k-1 - System ROM Versions to be supported 1. U60 v1.54 (01/13/2022) 2. U60 v1.58 (04/08/2022) Note: In case of using newer System ROM from the above version, it has already applied equivalent enhancements. Updating the System ROM isn't needed. Be sure to check the System ROM version and date with the following procedures. Select an arbitrary procedure and check the version before and after the update. ** System Utilities ** You can check the System ROM version and date by the following procedure. 1. Power on the system and the contents of process by POST (Power On Self- Test) will be shown on the screen. After a short time, the following message is shown. Press key, "System Utilities" is started. [F9] System Utilities 2. After starting "System Utilities", select "System Information". 3. Select "Firmware Information". 4. Each firmware version is shown on the screen. The System ROM version and date can be seen at "System ROM" option. Note: After checking the System ROM version, press the key or select "Exit" to exit the System Utilities. Note: About detail of "System Utilities" usage, refer to "1. System Utilities" section in the chapter of "Useful Features" of the maintenance guide. ** Windows(R) OS ** You can check the System ROM date by a following procedure. 1. Hold down key and press key. 2. In the "Run" dialog box, type "msinfo32" and then click "OK". 3. After "System Information" has started, select "System Summary". 4. Check the System ROM version by the profile of "BIOS Version/Date". ** Linux(R) OS ** You can check the System ROM date by a following procedure. 1. Launch the terminal such as xterm. 2. Execute the command as follows. # /usr/sbin/dmidecode | less Note: "#" means prompt. You do not need to input "#". 3. Check the System ROM date by "BIOS Information->Release Date". Note: The dmidecode command has to be installed. ================================================================================ Notes ================================================================================ ** Notes in general ** * Refer to "license_en.txt" about the user license agreement. * When you install the system ROM, the flashing mechanism writes over the backup ROM and saves current ROM as a backup, enabling you to switch easily to the alternate ROM version if the new ROM becomes corrupted for any reason. This feature protects the existing ROM version, even if you experience a power failure while flashing the ROM. * When Windows(R) BitLocker(TM) function is set to "Enabled", install the System ROM after making the function "Disabled". Then make the function "Enabled" after install and reboot of the system. If you install the system ROM without making the function "Disabled", you may need the recovery password when you boot the system. * This software does not support a virtualized environment such as hyper visor, guest OS, etc. Please install either on the OS which this software supports or with the method of offline installation. * To meet firmware dependencies, you can update iLO firmware by latest Starter Pack. And you can update Server Platform Services(SPS) firmware by latest "Server Platform Services(SPS) firmware update module". You can download latest update module(s) from the following web site. https://www.nec.com/express ("Support & Downloads" of the page top - PCs & Servers - Servers - Downloads - Select Model) ** Note for Windows(R) OS environment and Linux(R) OS environment ** * This software will access to iLO5 (Baseboard Management Controller). It is required that the "iLO 5 Channel Interface Driver" (CHIF) must be installed. The CHIF driver can be installed by using EXPRESSBUILDER or "Starter Pack". -------------------------------------------------------------------------------- [Revision history] Version:1.60 (07/14/2022) Enhancements and problem fixes: - Updated microcode for Processor. This version mitigates security vulnerability ofCVE-2022-21233. Intel(R) Xeon(R) E Processor Intel(R) Pentium(R) Gold Processor Series - This version mitigates a security vulnerability (CVE-2022-0778, CVE-2022-1292, CVE-2022-2068) in OpenSSL. - This version mitigates a security vulnerability (CVE-2022-27405) in FreeType library. - This version mitigates a security vulnerability (CVE-2018-25032) in zlib library. - Addressed an issue where the system fails to boot OpenShift Container Platform when Boot Mode option was set to UEFI Mode and the UEFI Optimized Boot option was set to Enabled. System Configuration > BIOS/Platform Configuration (RBSU) > Boot Options > Boot Mode System Configuration > BIOS/Platform Configuration (RBSU) > Boot Options > UEFI Optimized Boot - Addressed an issue where RAID controller names were not displayed correctly in the PCIe Device Configuration menu in RBSU or the One-Time Boot menu when the Select Language option in System Utilities was set to non-English. System Configuration > BIOS/Platform Configuration (RBSU) > PCIe Device Configuration Version:1.58 (04/18/2022) Enhancements and problem fixes: - Updated microcode for Processor. Intel(R) Xeon(R) E Processor Intel(R) Pentium(R) Gold Processor Series - Addressed following security vulnerabilities. CVE-2022-21151, CVE-2022-0005, CVE-2021-33122, CVE-2021-33123, CVE-2021-33124, CVE-2021-33103 Version:1.56 (03/24/2022) Enhancements and problem fixes: - Updated microcode for Processor. Intel(R) Xeon(R) E Processor Intel(R) Pentium(R) Gold Processor Series - Addressed an issue where Windows Server 2022 has a unknown device in Microsoft(R) Device Manager when Microsoft(R) Secured-core Support option or Intel(R) TXT Support option is enabled. System Configuration > BIOS/Platform Configuration (RBSU) > Server Security > Microsoft(R) Secured-core Support System Configuration > BIOS/Platform Configuration (RBSU) > Server Security > Intel Security Options > Intel(R) TXT Support -------------------------------------------------------------------------------- [Copyright and Trademark] All contents on this software are the copyright of NEC Corporation or the third-party software developer. All other contents mentioned herein are copyright of their respective owners. Microsoft, Windows, Windows Server are trademarks or registered trademarks of Microsoft Corporation in the United States and other countries. Linux(R) is a registered trademark of Linus Torvalds in the United States and other countries. Red Hat is a trademark or a registered trademark of Red Hat Inc. in the United States and other countries. All other company names and product names mentioned herein are registered trademarks or trademarks of their respective owners. -------------------------------------------------------------------------------- Copyright NEC Corporation 2022