QID 730605

Date Published: 2022-09-06

QID 730605: Hewlett Packard Enterprise (HPE) Integrated Lights-Out 5 (iLO 5) Multiple Vulnerabilities (HPESBHF04333)

HPE Integrated Lights-Out (iLO) is an embedded server management technology used for out-of-band management.

Multiple local and adjacent security vulnerabilities have been identified in HPE Integrated Lights-Out 5 (iLO 5) firmware. Exploitation of these vulnerabilities could potentially result in arbitrary code execution, denial of service (DoS), sensitive information disclosure, and unauthorized data modification leading to a loss of confidentiality, integrity, and availability.

Affected Versions:
HP Integrated Lights-Out 5 (iLO 5) firmware versions prior to v2.71

QID Detection Logic(Unauthenticated):
This QID checks for vulnerable version of HPE Integrated Lights-Out via an HTTP request to "xmldata?item=All" URL.

The vulnerability could impact the confidentiality, integrity and availability highly

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Critical - 8.3 severity.
  • Solution

    Customers are advised to visit HPESBHF04333 for details pertaining to this vulnerability.

    Software Advisories
    Advisory ID Software Component Link
    HPESBHF04333 URL Logo support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=emr_na-hpesbhf04333en_us