QID 730841

Date Published: 2023-07-28

QID 730841: Hewlett Packard Enterprise (HPE) Integrated Lights-Out 4 (iLO 4) Denial of Service (DoS) (HPESBHF04240)

A potential security vulnerability has been identified in Integrated Lights-Out 4 (iLO 4). The vulnerability could allow remote Denial of Service..

Affected Versions:
HPE Integrated Lights-Out 4 (iLO 4) - Prior to version 2.80

QID Detection Logic(Unauthenticated):
This QID checks for vulnerable version of HPE Integrated Lights-Out via an HTTP request to "xmldata?item=All" URL.

Successful exploitation of these vulnerabilities may lead to Denial of Service

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution

    Customers are advised to visit HPESBHF04240 to remediate this vulnerability.

    CVEs related to QID 730841

    Software Advisories
    Advisory ID Software Component Link
    HPESBHF04240 URL Logo support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=emr_na-hpesbhf04240en_us