QID 730961

QID 730961: Hewlett Packard Enterprise (HPE) Integrated Lights-Out 6 (iLO 6) and Integrated Lights-Out 5 (iLO 5) Denial of Service (DoS) (HPESBHF04544)

A potential security vulnerability has been identified in HPE Integrated Lights-Out 5 (iLO 5), and HPE Integrated Lights-Out 6 (iLO 6). The vulnerability could be remotely exploited to allow denial of service..

Affected Versions:
HPE Integrated Lights-Out 6 (iLO 6) - Prior to iLO 6 v1.53

HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers - Prior to iLO 5 v2.98

QID Detection Logic(Unauthenticated):
This QID checks for vulnerable version of HPE Integrated Lights-Out via an HTTP request to xmldata?item=All URL.

Successful exploitation of these vulnerabilities may lead to Denial of Service

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution

    Customers are advised to visit HPESBHF04544 to remediate this vulnerability.

    CVEs related to QID 730961

    Software Advisories
    Advisory ID Software Component Link
    HPESBHF04544 URL Logo support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=hpesbhf04544en_us