QID 731045
Date Published: 2023-12-21
QID 731045: Hewlett Packard Enterprise (HPE) Integrated Lights-Out (iLO) Remote Authentication Bypass Vulnerability (HPESBHF04584)
HPE Integrated Lights-Out (iLO) is an embedded server management technology used for out-of-band management.
A vulnerability exists in affected versions of HPE Integrated Lights-Out (iLO), that could allow an unauthenticated, remote attacker to bypass authentication mechanisms on a targeted system.
Affected Versions:
HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers - v2.63 through versions prior to v3.00
HPE Integrated Lights-Out 6 (iLO 6) - v1.05 through versions prior to v1.55
QID Detection Logic(Unauthenticated):
This QID checks for vulnerable version of HPE Integrated Lights-Out via an HTTP request to "xmldata?item=All" URL.
Successful exploitation allows an unauthenticated, remote attacker to bypass authentication on targeted systems.
CVEs related to QID 731045
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| HPESBHF04584 |
|