QID 730068

Date Published: 2021-05-03

QID 730068: HPE Integrated Lights-Out (iLO) Remote Memory Corruption Vulnerability (hpesbhf04106)

HPE Integrated Lights-Out (iLO) is an embedded server management technology used for out-of-band management. A potential security vulnerability has been identified in Integrated Lights-Out 5 (iLO 5) and Integrated Lights-Out 4 (iLO 4) firmware.

Affected Versions:
HP Integrated Lights-Out 5 (iLO 4) firmware versions prior to v2.33
HP Integrated Lights-Out 4 (iLO 4) firmware versions prior to v2.77

QID Detection Logic(Unauthenticated):
This QID checks for vulnerable version of HPE Integrated Lights-Out via an HTTP request to "xmldata?item=All" URL.

The vulnerability could be remotely exploited to cause memory corruption.

  • CVSS V3 rated as High - 7.3 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution

    Customers are advised to visit HPSBHF03275 to remediate this vulnerability.

    CVEs related to QID 730068

    Software Advisories
    Advisory ID Software Component Link
    hpesbhf04106 URL Logo support.hpe.com/hpesc/public/docDisplay?docId=hpesbhf04106en_us