QID 730953

Date Published: 2023-10-25

QID 730953: Hewlett Packard Enterprise (HPE) OneView Multiple Vulnerabilities

HPE OneView is an IT infrastructure management software that streamlines IT operations and controls all of your systems via a single global dashboard.

Potential security vulnerabilities have been identified in Hewlett Packard Enterprise OneView Software. These vulnerabilities could be remotely exploited to allow authentication bypass, disclosure of sensitive information, and denial of service.

Affected Version
All versions prior to 6.60.05
HPE OneView 7.00.00
HPE OneView 7.10.00
HPE OneView 7.20.00
HPE OneView 8.00.00
HPE OneView 8.10.00
HPE OneView 8.20.00
HPE OneView 8.30.00
HPE OneView 8.40.00
QID detection logic (Un-Auth)
This qid send GET request to /rest/appliance/nodeinfo/version to check software version

On successful exploitation an attacker can perform Authentication Bypass, Denial of Service (DoS), Disclosure of Sensitive Information attacks.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Vendor has released patched version. Please refer to HPE advisory: here for patching details

    CVEs related to QID 730953

    Software Advisories
    Advisory ID Software Component Link
    HPESBGN04530 URL Logo support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=hpesbgn04530en_us