QID 730599
Date Published: 2022-08-29
QID 730599: HP Integrated Lights-Out 4 (HPiLO) Security Enforcement Disabled Vulnerability
HP Integrated Lights-Out 4 (HPiLO) Security Enforcement Disabled function allows any arbitrary username/password to login and manage the HPiLO without any authorization controls. The iLO Security Override Switch grants the administrator full access to the iLO processor.
QID Detection logic (Unauthenticated): This QID checks for vulnerable HP iLO targets by trying to login with arbitrary credentials.
Enabling the security override switch allows a user to login with arbitrary username/password with admin privileges.
Solution
Customer's are advised to disable the HP iLO switch.
Vendor References
- HP Integrated Lights-Out 4 User Manual -
www.manualsdir.com/manuals/397253/hp-integrated-lights-out-4.html?page=62
CVEs related to QID 730599
Software Advisories
| Advisory ID | Software | Component | Link |
|---|