QID 730100

Date Published: 2021-06-02

QID 730100: HPE Integrated Lights-Out 5 (iLO 5) and Integrated Lights-Out 4 (iLO 4) Multiple Vulnerabilities (HPESBHF04133, HPESBHF04134, HPESBHF04121)

HPE Integrated Lights-Out (iLO) is an embedded server management technology used for out-of-band management.

HPE Integrated Lights-Out (iLO) firmware suffers from local buffer overflow and multiple client side vulnerabilities like XSS.

Affected Versions:
HPE Integrated Lights-Out 5 (iLO 5) Prior to v2.44
HPE Integrated Lights-Out 4 (iLO 4) Prior to v2.78

NOTE:
HPESBHF04133: Applicable for HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers - Prior to version 2.44
HPESBHF04121: Applicable for HPE Integrated Lights-Out 4 (iLO 4) - Prior to version 2.78
HPESBHF04134: Applicable for HPE Integrated Lights-Out 5(iLO 5) for HPE Gen10 Servers and HPE Integrated Lights-Out 4 (iLO 4)

QID Detection Logic(Unauthenticated):
This QID checks for vulnerable version of HPE Integrated Lights-Out via an HTTP request to "xmldata?item=All" URL.

Successful exploitation of these vulnerabilities may allow an privileged attacker to execute arbitrary code on the target.

  • CVSS V3 rated as High - 6.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution

    Customers are advised to visit HPESBHF04133, HPESBHF04134, HPESBHF04121 to remediate this vulnerability.

    Software Advisories
    Advisory ID Software Component Link
    HPESBHF04121 URL Logo support.hpe.com/hpesc/public/docDisplay?docId=hpesbhf04121en_us
    HPESBHF04133 URL Logo support.hpe.com/hpesc/public/docDisplay?docId=hpesbhf04133en_us
    HPESBHF04134 URL Logo support.hpe.com/hpesc/public/docDisplay?docId=hpesbhf04134en_us